PT-2026-86419 · Grav · Grav-Plugin-Form
CVSS v4.0
6.9
Medium
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X |
Name of the Vulnerable Software and Affected Versions
Grav Form Plugin versions prior to 9.1.22
Description
Insufficient page authorization verification occurs when resolving forms by name across pages. This allows anonymous visitors to execute form actions—such as saving, uploading, emailing, or calling—defined on unpublished or login-restricted pages. An attacker can trigger these actions by sending a POST request to any public page using the name of a restricted form.
Recommendations
Update Grav Form Plugin to version 9.1.22 or later.
Fix
Missing Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Grav-Plugin-Form