PT-2026-63975 · Grav · Api Plugin
CVSS v3.1
8.5
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
Grav API Plugin versions prior to 1.0.10
Description
Authenticated users with
api.config.write privilege can modify security-critical plugin configuration scopes. This allows attackers to disable site-wide rate limiting, facilitating credential brute-forcing attacks, and reconfigure Cross-Origin Resource Sharing (CORS) policies to include attacker-controlled origins with credentials enabled.Recommendations
Update Grav API Plugin to version 1.0.10 or later.
Exploit
Fix
Missing Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Api Plugin