PT-2026-81137 · Grav · Grav Login
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Grav Login plugin versions prior to 1.0.16
Description
Insufficient validation of the target account privilege level occurs in the
onApiUserListRowAction unlock handler. An attacker possessing api.users.write permission can clear login lockout counters on admin.super accounts. This action removes brute-force protection from the highest-privilege accounts without the attacker needing equivalent administrative permissions.Recommendations
Update Grav Login plugin to version 1.0.16 or later.
Fix
Incorrect Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Grav Login