A Stored Cross-Site Scripting (XSS) vulnerability was identified in the /admin/config/site endpoint of the Grav application. This vulnerability allows attackers to inject malicious scripts into the data[taxonomies] parameter. The injected payload is stored on the server and automatically executed in the browser of any user who accesses the affected site configuration, resulting in a persistent attack vector.
Vulnerable Endpoint: POST /admin/config/site
Parameter: data[taxonomies]
The application does not properly validate or sanitize input in the data[taxonomies] field. As a result, an attacker can inject JavaScript code, which is stored in the site configuration and later rendered in the administrative interface or site output, causing automatic execution in the user's browser.
Payload:
"><script>alert('XSS-PoC')</script>
Log in to the Grav Admin Panel with sufficient permissions to modify site configuration.
Navigate to Configuration > Site.
In the Taxonomies Types field (which maps to data[taxonomies]), insert the payload above:
"><script>alert('XSS-PoC')</script>
Save the configuration.
Stored XSS attacks can lead to severe consequences, including:
Session hijacking: Stealing cookies or authentication tokens to impersonate users
Credential theft: Harvesting usernames and passwords using malicious scripts
Malware delivery: Distributing unwanted or harmful code to victims
Privilege escalation: Compromising administrative users through persistent scripts
Data manipulation or defacement: Changing or disrupting site content
Reputation damage: Eroding trust among site users and administrators
by CVE-Hunters
{
"cwe_ids": [
"CWE-79"
],
"github_reviewed": true,
"github_reviewed_at": "2025-12-02T01:23:19Z",
"nvd_published_at": "2025-12-01T22:15:50Z",
"severity": "MODERATE"
}