An IDOR (Insecure Direct Object Reference) vulnerability in the Grav CMS Admin Panel allows low-privilege users to access sensitive information from other accounts. Although direct account takeover is not possible, admin email addresses and other metadata can be exposed, increasing the risk of phishing, credential stuffing, and social engineering.
/admin/accounts/users/{username}Description:
Requesting another user’s account details (e.g., /admin/accounts/users/admin) as a low-privilege user returns an HTTP 403 Forbidden response.
However, sensitive information such as the admin’s email address is still present in the response source, specifically in the <title> tag.
system/src/Grav/Common/Flex/Types/Users/UserCollection.php
system/blueprints/flex/user-accounts.yaml
This is a classic IDOR vulnerability, where object references (usernames) are not properly protected from unauthorized enumeration.
Log in as a non-privileged user (0-privilege account).
Access another user’s endpoint, for example:
GET /admin/accounts/users/admin
Observe the HTTP 403 Forbidden response.
Inspect the page source; sensitive data such as the admin email can be seen in the <title> tag.
PoC Video:
https://drive.google.com/file/d/1lY_qwqSkN5sPNmHvXGOk6R1mdIgVt71H/view
We request a CVE ID for this vulnerability once validated.
Please credit the discovery to:
{
"cwe_ids": [
"CWE-639"
],
"github_reviewed": true,
"github_reviewed_at": "2025-12-02T00:39:01Z",
"nvd_published_at": "2025-12-01T22:15:50Z",
"severity": "MODERATE"
}