<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Wed, 07 Oct 2026 04:16:43 +0000</lastBuildDate>
    <item>
      <title>cnvd-2025-30338</title>
      <link>https://cve.radiocsirt.org/vuln/cnvd-2025-30338</link>
      <description>cnvd-2025-30338</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cnvd-2025-30338</guid>
    </item>
    <item>
      <title>EUVD-2026-262345</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-262345</link>
      <description>EUVD-2026-262345</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-262345</guid>
    </item>
    <item>
      <title>fkie_cve-2025-66304</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2025-66304</link>
      <description>&lt;p&gt;Grav is a file-based Web platform. Prior to 1.8.0-beta.27, users with read access on the user account management section of the admin panel can view the password hashes of all users, including the admin user. This exposure can potentially lead to privilege escalation if an attacker can crack these password hashes. This vulnerability is fixed in 1.8.0-beta.27.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Grav is a file-based Web platform. Prior to 1.8.0-beta.27, users with read access on the user account management section of the admin panel can view the password hashes of all users, including the admin user. This exposure can potentially lead to privilege escalation if an attacker can crack these password hashes. This vulnerability is fixed in 1.8.0-beta.27.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2025-66304</guid>
    </item>
    <item>
      <title>GHSA-gq3g-666w-7h85 — Grav Exposes Password Hashes Leading to privilege escalation</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-gq3g-666w-7h85</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Packagist: getgrav/grav&lt;/p&gt;
&lt;p&gt;# Exposure of Password Hashes Leading to privilege escalation
**Severity Rating:** Medium&lt;/p&gt;
&lt;p&gt;**Vector:** Privilege Escalation&lt;/p&gt;
&lt;p&gt;**CVE:** XXX&lt;/p&gt;
&lt;p&gt;**CWE:** 200 - Exposure of Sensitive Information&lt;/p&gt;
&lt;p&gt;**CVSS Score:** 6.2&lt;/p&gt;
&lt;p&gt;**CVSS Vector:** CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:L&lt;/p&gt;
&lt;p&gt;## Analysis&lt;/p&gt;
&lt;p&gt;It was observed that if a users is given read access on the user account management section of the admin panel can view the password hashes of all users, including the admin user. This exposure can potentially lead to privilege escalation if an attacker can crack these password hashes.&lt;/p&gt;
&lt;p&gt;An attacker with read access can: 
* View and potentially crack the password hashes.
* Gain administrative access by cracking the admin password hash.
* Escalate privileges and compromise the entire admin panel.&lt;/p&gt;
&lt;p&gt;## Proof of Concept&lt;/p&gt;
&lt;p&gt;1) Give read access to user accounts to a random user as shown in the following figures:
  ![grav0](https://github.com/user-attachments/assets/020a4b47-e577-49cb-8392-bfb61491199d)
  ![grav2](https://github.com/user-attachments/assets/97fbfc46-c541-4559-9541-2b9b5de86c0e)&lt;/p&gt;
&lt;p&gt;2) Log in to the admin panel with an account that has read access to user accounts and navigate to the user account management section.&lt;/p&gt;
&lt;p&gt;3) Go to the admin profile `http://127.0.0.1/admin/accounts/users/admin`; The password is not display. Try inspecting the page source code as shown in the following figures:
  ![grav2-1](https://github.com/user-attachments/assets/057c9c14-f928-4584-99ae-4939f63dda57)
  
   Y…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Packagist: getgrav/grav&lt;/p&gt;
&lt;p&gt;# Exposure of Password Hashes Leading to privilege escalation
**Severity Rating:** Medium&lt;/p&gt;
&lt;p&gt;**Vector:** Privilege Escalation&lt;/p&gt;
&lt;p&gt;**CVE:** XXX&lt;/p&gt;
&lt;p&gt;**CWE:** 200 - Exposure of Sensitive Information&lt;/p&gt;
&lt;p&gt;**CVSS Score:** 6.2&lt;/p&gt;
&lt;p&gt;**CVSS Vector:** CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:L&lt;/p&gt;
&lt;p&gt;## Analysis&lt;/p&gt;
&lt;p&gt;It was observed that if a users is given read access on the user account management section of the admin panel can view the password hashes of all users, including the admin user. This exposure can potentially lead to privilege escalation if an attacker can crack these password hashes.&lt;/p&gt;
&lt;p&gt;An attacker with read access can: 
* View and potentially crack the password hashes.
* Gain administrative access by cracking the admin password hash.
* Escalate privileges and compromise the entire admin panel.&lt;/p&gt;
&lt;p&gt;## Proof of Concept&lt;/p&gt;
&lt;p&gt;1) Give read access to user accounts to a random user as shown in the following figures:
  ![grav0](https://github.com/user-attachments/assets/020a4b47-e577-49cb-8392-bfb61491199d)
  ![grav2](https://github.com/user-attachments/assets/97fbfc46-c541-4559-9541-2b9b5de86c0e)&lt;/p&gt;
&lt;p&gt;2) Log in to the admin panel with an account that has read access to user accounts and navigate to the user account management section.&lt;/p&gt;
&lt;p&gt;3) Go to the admin profile `http://127.0.0.1/admin/accounts/users/admin`; The password is not display. Try inspecting the page source code as shown in the following figures:
  ![grav2-1](https://github.com/user-attachments/assets/057c9c14-f928-4584-99ae-4939f63dda57)
  
   Y…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-gq3g-666w-7h85</guid>
    </item>
  </channel>
</rss>
