Home
Home
Trends
Trends
Vulnerabilities
Vulnerabilities
News
News
Researchers
Researchers
Why dbugs?
Why dbugs?
Settings

Canhieu

#33155of 57,349
8.6Total CVSS
Vulnerabilities · 1
PT-2026-99342
8.6
2026-09-26
Grav · Grav · CVE-2026-100671
**Name of the Vulnerable Software and Affected Versions** Grav versions 1.7.x Grav versions 2.0.0 through 2.0.24 **Description** Page content created by a user with page-write permissions is rendered through a Twig sandbox that allowlists the `get cookie()` function. This function returns any cookie sent with the request, including session cookies. Because the read is performed server-side using `filter input(INPUT COOKIE, ...)`, security attributes like HttpOnly, Secure, and SameSite do not provide protection. The resulting output is stored in a page-content cache that lacks session or user dimensions. Consequently, a user with page-write access can capture the session identifier of an administrator who views the page. This cached identifier is then served to unauthenticated visitors, allowing them to replay the cookie and authenticate as the administrator. In versions 2.0.19 through 2.0.24, the `security.twig content.process enabled` setting defaults to true, and the `Security::applyTwigContentDefault()` function ensures content Twig runs on every page by default. **Recommendations** Update Grav versions 2.0.0 through 2.0.24 to version 2.0.25. At the moment, there is no information about a newer version that contains a fix for this vulnerability for versions 1.7.x.