Grav is a file-based Web platform. Prior to 1.8.0-beta.27, a privilege escalation vulnerability exists in Grav’s Admin plugin due to the absence of username uniqueness validation when creating users. A user with the create user permission can create a new account using the same username as an existing administrator account, set a new password/email, and then log in as that administrator. This effectively allows privilege escalation from limited user-manager permissions to full administrator access. This vulnerability is fixed in 1.8.0-beta.27.
A product incorrectly assigns a privilege to a particular actor, creating an unintended sphere of control for that actor.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Grav | Getgrav | 1.7.49.5 (including) | 1.8.0 (excluding) |
| Grav | Getgrav | 1.8.0-beta1 (including) | 1.8.0-beta1 (including) |
| Grav | Getgrav | 1.8.0-beta10 (including) | 1.8.0-beta10 (including) |
| Grav | Getgrav | 1.8.0-beta11 (including) | 1.8.0-beta11 (including) |
| Grav | Getgrav | 1.8.0-beta12 (including) | 1.8.0-beta12 (including) |
| Grav | Getgrav | 1.8.0-beta13 (including) | 1.8.0-beta13 (including) |
| Grav | Getgrav | 1.8.0-beta14 (including) | 1.8.0-beta14 (including) |
| Grav | Getgrav | 1.8.0-beta15 (including) | 1.8.0-beta15 (including) |
| Grav | Getgrav | 1.8.0-beta16 (including) | 1.8.0-beta16 (including) |
| Grav | Getgrav | 1.8.0-beta17 (including) | 1.8.0-beta17 (including) |
| Grav | Getgrav | 1.8.0-beta18 (including) | 1.8.0-beta18 (including) |
| Grav | Getgrav | 1.8.0-beta19 (including) | 1.8.0-beta19 (including) |
| Grav | Getgrav | 1.8.0-beta2 (including) | 1.8.0-beta2 (including) |
| Grav | Getgrav | 1.8.0-beta20 (including) | 1.8.0-beta20 (including) |
| Grav | Getgrav | 1.8.0-beta21 (including) | 1.8.0-beta21 (including) |
| Grav | Getgrav | 1.8.0-beta22 (including) | 1.8.0-beta22 (including) |
| Grav | Getgrav | 1.8.0-beta23 (including) | 1.8.0-beta23 (including) |
| Grav | Getgrav | 1.8.0-beta24 (including) | 1.8.0-beta24 (including) |
| Grav | Getgrav | 1.8.0-beta25 (including) | 1.8.0-beta25 (including) |
| Grav | Getgrav | 1.8.0-beta26 (including) | 1.8.0-beta26 (including) |
| Grav | Getgrav | 1.8.0-beta3 (including) | 1.8.0-beta3 (including) |
| Grav | Getgrav | 1.8.0-beta4 (including) | 1.8.0-beta4 (including) |
| Grav | Getgrav | 1.8.0-beta5 (including) | 1.8.0-beta5 (including) |
| Grav | Getgrav | 1.8.0-beta6 (including) | 1.8.0-beta6 (including) |
| Grav | Getgrav | 1.8.0-beta7 (including) | 1.8.0-beta7 (including) |
| Grav | Getgrav | 1.8.0-beta8 (including) | 1.8.0-beta8 (including) |
| Grav | Getgrav | 1.8.0-beta9 (including) | 1.8.0-beta9 (including) |