PT-2026-99343 · Grav Cms · Comments Plugin
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
getgrav/grav-plugin-comments versions prior to 1.2.11
Description
The Comments plugin for Grav CMS registers an admin handler that returns comment data as JSON without performing an authentication check. The handler relies on the
isAdmin() function, which only verifies if the admin service is registered on the current route instead of confirming the visitor's authentication status. This allows an unauthenticated remote attacker to access the /admin/comments/page:<n> endpoint and retrieve comments from the last 7 days, including commenter email addresses and the absolute server filesystem path of the data file. This issue affects sites using the classic Admin plugin with Comments enabled.Recommendations
Update to version 1.2.11.
Exploit
Fix
Missing Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Comments Plugin