CyberRota Analysis
AI-GeneratedGrav versions prior to 2.0.14 are vulnerable due to inadequate access control in the core group blueprint, allowing delegated admin.users operators to escalate their privileges to super-admin. This vulnerability enables unauthorized users to gain elevated access, including scheduler and Twig evaluation capabilities, posing a significant security risk. Organizations using Grav should prioritize patching to mitigate potential exploitation.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
Grav before 2.0.14 fails to guard the access field in the core group blueprint with the required security@: admin.super restriction. A delegated admin.users operator can save a group with access[admin][super]=true to escalate to super-admin, gaining scheduler and Twig evaluation capabilities.