PT-2026-99338 · Grav · Grav-Plugin-Login
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
grav-plugin-login versions 3.8.7 through 3.9.6
Description
A flaw exists where the two-factor authentication (2FA) challenge can be bypassed for content protected by the
authenticated() Twig function or the [authenticated] shortcode. This occurs because the Login::isAuthenticated() function only verifies the session flag for successful password entry rather than confirming the entire login process is complete. Consequently, a session awaiting a 2FA code is incorrectly treated as fully authenticated. An attacker possessing a user's password can access member-only content rendered by the no-argument authenticated() form, the group authenticated(null, 'group') form, or the [authenticated] shortcode. Additionally, the [guest] shortcode is evaluated prematurely. The impact is limited to the disclosure of this specific content; the attacker cannot obtain a full session, access pages protected by an access: rule, or perform actions as the user. The authenticated('some.permission') form is not affected as it utilizes UserObject::authorize().Recommendations
Update grav-plugin-login to version 3.9.7.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Grav-Plugin-Login