216.73.216.197

CVE-2025-66309

· Published 01/12/2025 22:15 · Modified 03/12/2025 21:56

Labels: CVE-2025-66309 2025-12-01CVE-2025-66309CWE-79[email protected]

Essential information

Published
01/12/2025 22:15
Modified
03/12/2025 21:56
Author
Creator
CVSS
6.2 MEDIUM (v3) 6.2 MEDIUM (v4.0)
CISA KEV
No
CWE
CVSS vector

CVSS metrics

Description

This admin plugin for Grav is an HTML user interface that provides a convenient way to configure Grav and easily create and modify pages. Prior to 1.11.0-beta.1, a Reflected Cross-Site Scripting (XSS) vulnerability was identified in the /admin/pages/[page] endpoint of the Grav application. This vulnerability allows attackers to inject malicious scripts into the data[header][content][items] parameter. This vulnerability is fixed in 1.11.0-beta.1.

NVD status

Status
Analyzed — CVE has had analysis completed and all data associations made.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
getgrav / grav-plugin-admin cpe:2.3:a:getgrav:grav-plugin-admin:*:*:*:*:*:*:*:*

References