PT-2026-99342 · Grav · Grav
CVSS v4.0
8.6
High
| Vector | AV:N/AC:L/AT:N/PR:L/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Grav versions 1.7.x
Grav versions 2.0.0 through 2.0.24
Description
Page content created by a user with page-write permissions is rendered through a Twig sandbox that allowlists the
get cookie() function. This function returns any cookie sent with the request, including session cookies. Because the read is performed server-side using filter input(INPUT COOKIE, ...), security attributes like HttpOnly, Secure, and SameSite do not provide protection. The resulting output is stored in a page-content cache that lacks session or user dimensions. Consequently, a user with page-write access can capture the session identifier of an administrator who views the page. This cached identifier is then served to unauthenticated visitors, allowing them to replay the cookie and authenticate as the administrator. In versions 2.0.19 through 2.0.24, the security.twig content.process enabled setting defaults to true, and the Security::applyTwigContentDefault() function ensures content Twig runs on every page by default.Recommendations
Update Grav versions 2.0.0 through 2.0.24 to version 2.0.25.
At the moment, there is no information about a newer version that contains a fix for this vulnerability for versions 1.7.x.
Exploit
Fix
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Grav