<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-07T02:27:30.375066+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cnvd-2025-30338</id>
    <title>cnvd-2025-30338</title>
    <updated>2026-10-07T02:27:30.379393+00:00</updated>
    <content>cnvd-2025-30338</content>
    <link href="https://cve.radiocsirt.org/vuln/cnvd-2025-30338"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-262345</id>
    <title>EUVD-2026-262345</title>
    <updated>2026-10-07T02:27:30.379425+00:00</updated>
    <content>EUVD-2026-262345</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-262345"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2025-66304</id>
    <title>fkie_cve-2025-66304</title>
    <updated>2026-10-07T02:27:30.379440+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Grav is a file-based Web platform. Prior to 1.8.0-beta.27, users with read access on the user account management section of the admin panel can view the password hashes of all users, including the admin user. This exposure can potentially lead to privilege escalation if an attacker can crack these password hashes. This vulnerability is fixed in 1.8.0-beta.27.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2025-66304"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-gq3g-666w-7h85</id>
    <title>GHSA-gq3g-666w-7h85 — Grav Exposes Password Hashes Leading to privilege escalation</title>
    <updated>2026-10-07T02:27:30.379468+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Packagist: getgrav/grav</p>
<p># Exposure of Password Hashes Leading to privilege escalation
**Severity Rating:** Medium</p>
<p>**Vector:** Privilege Escalation</p>
<p>**CVE:** XXX</p>
<p>**CWE:** 200 - Exposure of Sensitive Information</p>
<p>**CVSS Score:** 6.2</p>
<p>**CVSS Vector:** CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:L</p>
<p>## Analysis</p>
<p>It was observed that if a users is given read access on the user account management section of the admin panel can view the password hashes of all users, including the admin user. This exposure can potentially lead to privilege escalation if an attacker can crack these password hashes.</p>
<p>An attacker with read access can: 
* View and potentially crack the password hashes.
* Gain administrative access by cracking the admin password hash.
* Escalate privileges and compromise the entire admin panel.</p>
<p>## Proof of Concept</p>
<p>1) Give read access to user accounts to a random user as shown in the following figures:
  ![grav0](https://github.com/user-attachments/assets/020a4b47-e577-49cb-8392-bfb61491199d)
  ![grav2](https://github.com/user-attachments/assets/97fbfc46-c541-4559-9541-2b9b5de86c0e)</p>
<p>2) Log in to the admin panel with an account that has read access to user accounts and navigate to the user account management section.</p>
<p>3) Go to the admin profile `http://127.0.0.1/admin/accounts/users/admin`; The password is not display. Try inspecting the page source code as shown in the following figures:
  ![grav2-1](https://github.com/user-attachments/assets/057c9c14-f928-4584-99ae-4939f63dda57)
  
   Y…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-gq3g-666w-7h85"/>
  </entry>
</feed>
