CVE-2025-66303
Grav is a file-based Web platform. Prior to 1.8.0-beta.27, A Denial of Service (DoS) vulnerability has been identified in Grav related to the handling of scheduled_at parameters. Specifically, the application fails to properly sanitize input for cron expressions. By manipulating the scheduled_at parameter with a malicious input, such as a single quote, the application admin panel becomes non-functional, causing significant disruptions to administrative operations. The only way to recover from this issue is to manually access the host server and modify the backup.yaml file to correct the corrupted cron expression. This vulnerability is fixed in 1.8.0-beta.27.
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H
- Puntuación base: 4.9
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.39%
- Percentil entre todas las CVEs puntuadas: 31
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
CWE
- CWE-400
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2025-66303",
"cveTags": [],
"metrics": {
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2025-66303",
"role": "CISA Coordinator",
"options": [
{
"exploitation": "poc"
},
{
"automatable": "no"
},
{
"technicalImpact": "partial"
}
],
"version": "2.0.3",
"timestamp": "2025-12-03T15:10:29.097271Z"
}
}
],
"cvssMetricV31": [
{
"type": "Secondary",
"source": "security-advisories@github.com",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 4.9,
"attackVector": "NETWORK",
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H",
"integrityImpact": "NONE",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "HIGH",
"confidentialityImpact": "NONE"
},
"impactScore": 3.6,
"exploitabilityScore": 1.2
}
]
},
"affected": [
{
"source": "security-advisories@github.com",
"affectedData": [
{
"vendor": "getgrav",
"product": "grav",
"versions": [
{
"status": "affected",
"version": "< 1.8.0-beta.27"
}
]
}
]
}
],
"published": "2025-12-01T22:15:49.913",
"references": [
{
"url": "https://github.com/getgrav/grav/commit/9d11094e4133f059688fad1e00dbe96fb6e3ead7",
"tags": [
"Patch"
],
"source": "security-advisories@github.com"
},
{
"url": "https://github.com/getgrav/grav/security/advisories/GHSA-x62q-p736-3997",
"tags": [
"Exploit",
"Third Party Advisory"
],
"source": "security-advisories@github.com"
},
{
"url": "https://github.com/getgrav/grav/security/advisories/GHSA-x62q-p736-3997",
"tags": [
"Exploit",
"Third Party Advisory"
],
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0"
}
],
"vulnStatus": "Analyzed",
"weaknesses": [
{
"type": "Secondary",
"source": "security-advisories@github.com",
"description": [
{
"lang": "en",
"value": "CWE-400"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Grav is a file-based Web platform. Prior to 1.8.0-beta.27, A Denial of Service (DoS) vulnerability has been identified in Grav related to the handling of scheduled_at parameters. Specifically, the application fails to properly sanitize input for cron expressions. By manipulating the scheduled_at parameter with a malicious input, such as a single quote, the application admin panel becomes non-functional, causing significant disruptions to administrative operations. The only way to recover from this issue is to manually access the host server and modify the backup.yaml file to correct the corrupted cron expression. This vulnerability is fixed in 1.8.0-beta.27."
},
{
"lang": "es",
"value": "Grav es una plataforma web basada en archivos. Versiones anteriores a 1.8.0-beta.27, se ha identificado una vulnerabilidad de denegación de servicio (DoS) en Grav relacionada con el manejo de los parámetros 'scheduled_at'. Específicamente, la aplicación no logra sanear correctamente la entrada para las expresiones cron. Al manipular el parámetro 'scheduled_at' con una entrada maliciosa, como una comilla simple, el panel de administración de la aplicación deja de funcionar, causando interrupciones significativas en las operaciones administrativas. La única forma de recuperarse de este problema es acceder manualmente al servidor host y modificar el archivo 'backup.yaml' para corregir la expresión cron corrupta. Esta vulnerabilidad se corrige en 1.8.0-beta.27."
}
],
"lastModified": "2026-09-26T00:10:00.127",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:getgrav:grav:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "0F068841-DBCC-41D5-8B24-BFCE51841E2E",
"versionEndExcluding": "1.8.0"
},
{
"criteria": "cpe:2.3:a:getgrav:grav:1.8.0:beta1:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "8A383F2E-C6BA-440B-B648-A3313B7D91C3"
},
{
"criteria": "cpe:2.3:a:getgrav:grav:1.8.0:beta10:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "F7EF2DEC-2798-4D0D-9C27-0F01BAFEAEFD"
},
{
"criteria": "cpe:2.3:a:getgrav:grav:1.8.0:beta11:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "530C6F64-F30B-4E93-9A12-D9625EA57483"
},
{
"criteria": "cpe:2.3:a:getgrav:grav:1.8.0:beta12:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "9AC28BF9-626D-4514-91F0-F81DAB5D3602"
},
{
"criteria": "cpe:2.3:a:getgrav:grav:1.8.0:beta13:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "307AA375-E531-4AE5-BA79-2F9D4DE7A05F"
},
{
"criteria": "cpe:2.3:a:getgrav:grav:1.8.0:beta14:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "C2E3E312-485D-42B0-B465-64B6438CDCAE"
},
{
"criteria": "cpe:2.3:a:getgrav:grav:1.8.0:beta15:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "5BE4B2F9-1B6D-4D18-916A-5C95A3213222"
},
{
"criteria": "cpe:2.3:a:getgrav:grav:1.8.0:beta16:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "763207F0-92D1-4274-A30A-DE634C5852C3"
},
{
"criteria": "cpe:2.3:a:getgrav:grav:1.8.0:beta17:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "1DE8F350-BA07-4DAA-AE4B-5E0A532B6828"
},
{
"criteria": "cpe:2.3:a:getgrav:grav:1.8.0:beta18:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "F9150B94-0DF3-43F3-9806-39787A6C0E4D"
},
{
"criteria": "cpe:2.3:a:getgrav:grav:1.8.0:beta19:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "BAA7C7EC-8FB2-445D-8A02-1743D87F5416"
},
{
"criteria": "cpe:2.3:a:getgrav:grav:1.8.0:beta2:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "7A6BEA2A-D534-4C9E-811A-8A46E214C46D"
},
{
"criteria": "cpe:2.3:a:getgrav:grav:1.8.0:beta20:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "7A644F57-FF39-4262-9796-7C4F3B0851C1"
},
{
"criteria": "cpe:2.3:a:getgrav:grav:1.8.0:beta21:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "B2AFB9E7-084E-497B-B0FC-CA6A5033C5BF"
},
{
"criteria": "cpe:2.3:a:getgrav:grav:1.8.0:beta22:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "5C5E8823-9083-4FFA-9897-CAD0340DCE68"
},
{
"criteria": "cpe:2.3:a:getgrav:grav:1.8.0:beta23:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "9C048938-E0EC-4AD0-9847-FD74E6770FE2"
},
{
"criteria": "cpe:2.3:a:getgrav:grav:1.8.0:beta24:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "F7B43876-1445-418A-9707-E692FDF62C4D"
},
{
"criteria": "cpe:2.3:a:getgrav:grav:1.8.0:beta25:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "94B209DE-01C6-41BA-B912-CF57849A9F7A"
},
{
"criteria": "cpe:2.3:a:getgrav:grav:1.8.0:beta26:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "AB53AA10-87A5-4010-8019-BF4AA5ABC12B"
},
{
"criteria": "cpe:2.3:a:getgrav:grav:1.8.0:beta3:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "775E0913-F3EF-4A55-B162-5BF9C6E2E641"
},
{
"criteria": "cpe:2.3:a:getgrav:grav:1.8.0:beta4:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "3C3E022E-35CB-40AD-959A-F39949E38BD3"
},
{
"criteria": "cpe:2.3:a:getgrav:grav:1.8.0:beta5:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "8779C813-A81A-4E21-AB86-6193933568BC"
},
{
"criteria": "cpe:2.3:a:getgrav:grav:1.8.0:beta6:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "B608EDD4-207A-41A7-A60D-496FDA8EAFEA"
},
{
"criteria": "cpe:2.3:a:getgrav:grav:1.8.0:beta7:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "AE1F2253-3EE0-4ADD-B8A5-C882A60FC626"
},
{
"criteria": "cpe:2.3:a:getgrav:grav:1.8.0:beta8:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "81D4C859-5560-42F1-ACD9-65210E523F28"
},
{
"criteria": "cpe:2.3:a:getgrav:grav:1.8.0:beta9:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "156707A7-9507-4AC1-9CD0-90E32836E9DF"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "security-advisories@github.com"
}