User Enumeration and Email Disclosure in Grav Admin Plugin
CVE-2025-66307
6.5MEDIUM
What is CVE-2025-66307?
The Grav Admin Plugin presents a vulnerability that allows attackers to exploit the 'Forgot Password' feature, disclosing valid usernames and their associated email addresses through different server responses. This flaw enables user enumeration, which can be exploited to carry out targeted attacks like password spraying and phishing. It is essential for users of the Grav Admin Plugin to upgrade to version 1.11.0-beta.1 or later to mitigate these risks.
Affected Version(s)
grav < 1.11.0-beta.1
