PT-2026-63977 · Grav · Grav-Plugin-Api
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Grav API Plugin versions prior to 1.0.10
Description
Insufficient validation of the
groups field within the InvitationsController::create() function allows authenticated users with api.users.write permissions to assign invited accounts to groups that grant api.super permissions. This enables an attacker to create invitation records with elevated group membership, granting the new account full super-admin API access regardless of the inviter's own permission level.Recommendations
Update Grav API Plugin to version 1.0.10 or later.
Exploit
Fix
LPE
Improper Privilege Management
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Grav-Plugin-Api