CVE-2025-66304
Grav is a file-based Web platform. Prior to 1.8.0-beta.27, users with read access on the user account management section of the admin panel can view the password hashes of all users, including the admin user. This exposure can potentially lead to privilege escalation if an attacker can crack these password hashes. This vulnerability is fixed in 1.8.0-beta.27.
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
- Puntuación base: 7.2
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.41%
- Percentil entre todas las CVEs puntuadas: 33
- Fecha de la puntuación: 5/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
🎯 Técnicas ATT&CK
Cómo se explota esta vulnerabilidad y qué consigue el atacante, en el lenguaje de MITRE ATT&CK.
- Explotación
T1210Exploitation of Remote Serviceslateral movement75 % - Impacto principal
T1552.007Container APIcredential access85 % - Impacto secundario
T1110.004Credential Stuffingcredential access70 %
Acceso remoto a datos sensibles (hashes de contraseña) requiriendo privilegios previos (PR:H) y sin interacción. Exposición de credenciales en admin panel permite crackeo offline para escalada.
Inferido por nuestro agente de análisis a partir de la descripción oficial, el vector CVSS y la CWE, y comprobado por un supervisor. Puede contener errores.
🛡️ Mitigaciones ATT&CK que cubren estas técnicas
Tecnologías afectadas (1)
CWE
- CWE-200, CWE-201
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2025-66304",
"cveTags": [],
"metrics": {
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2025-66304",
"role": "CISA Coordinator",
"options": [
{
"exploitation": "poc"
},
{
"automatable": "no"
},
{
"technicalImpact": "total"
}
],
"version": "2.0.3",
"timestamp": "2025-12-02T20:15:09.292478Z"
}
}
],
"cvssMetricV31": [
{
"type": "Secondary",
"source": "security-advisories@github.com",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 6.2,
"attackVector": "NETWORK",
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:L",
"integrityImpact": "HIGH",
"userInteraction": "NONE",
"attackComplexity": "HIGH",
"availabilityImpact": "LOW",
"privilegesRequired": "HIGH",
"confidentialityImpact": "HIGH"
},
"impactScore": 5.5,
"exploitabilityScore": 0.7
},
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 7.2,
"attackVector": "NETWORK",
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H",
"integrityImpact": "HIGH",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "HIGH",
"confidentialityImpact": "HIGH"
},
"impactScore": 5.9,
"exploitabilityScore": 1.2
}
]
},
"affected": [
{
"source": "security-advisories@github.com",
"affectedData": [
{
"vendor": "getgrav",
"product": "grav",
"versions": [
{
"status": "affected",
"version": "< 1.8.0-beta.27"
}
]
}
]
}
],
"published": "2025-12-01T22:15:50.080",
"references": [
{
"url": "https://github.com/getgrav/grav/commit/9d11094e4133f059688fad1e00dbe96fb6e3ead7",
"tags": [
"Patch"
],
"source": "security-advisories@github.com"
},
{
"url": "https://github.com/getgrav/grav/security/advisories/GHSA-gq3g-666w-7h85",
"tags": [
"Exploit",
"Vendor Advisory"
],
"source": "security-advisories@github.com"
},
{
"url": "https://github.com/getgrav/grav/security/advisories/GHSA-gq3g-666w-7h85",
"tags": [
"Exploit",
"Vendor Advisory"
],
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0"
}
],
"vulnStatus": "Analyzed",
"weaknesses": [
{
"type": "Secondary",
"source": "security-advisories@github.com",
"description": [
{
"lang": "en",
"value": "CWE-200"
},
{
"lang": "en",
"value": "CWE-201"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Grav is a file-based Web platform. Prior to 1.8.0-beta.27, users with read access on the user account management section of the admin panel can view the password hashes of all users, including the admin user. This exposure can potentially lead to privilege escalation if an attacker can crack these password hashes. This vulnerability is fixed in 1.8.0-beta.27."
},
{
"lang": "es",
"value": "Grav es una plataforma web basada en archivos. Versiones anteriores a 1.8.0-beta.27, los usuarios con acceso de lectura en la sección de gestión de cuentas de usuario del panel de administración pueden ver los hashes de contraseña de todos los usuarios, incluido el usuario administrador. Esta exposición puede conducir potencialmente a la escalada de privilegios si un atacante puede descifrar estos hashes de contraseña. Esta vulnerabilidad está corregida en 1.8.0-beta.27."
}
],
"lastModified": "2026-09-26T00:10:00.127",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:getgrav:grav:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "A9B3FCDC-ADBD-4023-9AC7-154642622421",
"versionEndExcluding": "1.8.0",
"versionStartIncluding": "1.7.46"
},
{
"criteria": "cpe:2.3:a:getgrav:grav:1.8.0:beta1:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "8A383F2E-C6BA-440B-B648-A3313B7D91C3"
},
{
"criteria": "cpe:2.3:a:getgrav:grav:1.8.0:beta10:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "F7EF2DEC-2798-4D0D-9C27-0F01BAFEAEFD"
},
{
"criteria": "cpe:2.3:a:getgrav:grav:1.8.0:beta11:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "530C6F64-F30B-4E93-9A12-D9625EA57483"
},
{
"criteria": "cpe:2.3:a:getgrav:grav:1.8.0:beta12:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "9AC28BF9-626D-4514-91F0-F81DAB5D3602"
},
{
"criteria": "cpe:2.3:a:getgrav:grav:1.8.0:beta13:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "307AA375-E531-4AE5-BA79-2F9D4DE7A05F"
},
{
"criteria": "cpe:2.3:a:getgrav:grav:1.8.0:beta14:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "C2E3E312-485D-42B0-B465-64B6438CDCAE"
},
{
"criteria": "cpe:2.3:a:getgrav:grav:1.8.0:beta15:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "5BE4B2F9-1B6D-4D18-916A-5C95A3213222"
},
{
"criteria": "cpe:2.3:a:getgrav:grav:1.8.0:beta16:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "763207F0-92D1-4274-A30A-DE634C5852C3"
},
{
"criteria": "cpe:2.3:a:getgrav:grav:1.8.0:beta17:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "1DE8F350-BA07-4DAA-AE4B-5E0A532B6828"
},
{
"criteria": "cpe:2.3:a:getgrav:grav:1.8.0:beta18:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "F9150B94-0DF3-43F3-9806-39787A6C0E4D"
},
{
"criteria": "cpe:2.3:a:getgrav:grav:1.8.0:beta19:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "BAA7C7EC-8FB2-445D-8A02-1743D87F5416"
},
{
"criteria": "cpe:2.3:a:getgrav:grav:1.8.0:beta2:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "7A6BEA2A-D534-4C9E-811A-8A46E214C46D"
},
{
"criteria": "cpe:2.3:a:getgrav:grav:1.8.0:beta20:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "7A644F57-FF39-4262-9796-7C4F3B0851C1"
},
{
"criteria": "cpe:2.3:a:getgrav:grav:1.8.0:beta21:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "B2AFB9E7-084E-497B-B0FC-CA6A5033C5BF"
},
{
"criteria": "cpe:2.3:a:getgrav:grav:1.8.0:beta22:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "5C5E8823-9083-4FFA-9897-CAD0340DCE68"
},
{
"criteria": "cpe:2.3:a:getgrav:grav:1.8.0:beta23:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "9C048938-E0EC-4AD0-9847-FD74E6770FE2"
},
{
"criteria": "cpe:2.3:a:getgrav:grav:1.8.0:beta24:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "F7B43876-1445-418A-9707-E692FDF62C4D"
},
{
"criteria": "cpe:2.3:a:getgrav:grav:1.8.0:beta25:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "94B209DE-01C6-41BA-B912-CF57849A9F7A"
},
{
"criteria": "cpe:2.3:a:getgrav:grav:1.8.0:beta26:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "AB53AA10-87A5-4010-8019-BF4AA5ABC12B"
},
{
"criteria": "cpe:2.3:a:getgrav:grav:1.8.0:beta3:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "775E0913-F3EF-4A55-B162-5BF9C6E2E641"
},
{
"criteria": "cpe:2.3:a:getgrav:grav:1.8.0:beta4:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "3C3E022E-35CB-40AD-959A-F39949E38BD3"
},
{
"criteria": "cpe:2.3:a:getgrav:grav:1.8.0:beta5:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "8779C813-A81A-4E21-AB86-6193933568BC"
},
{
"criteria": "cpe:2.3:a:getgrav:grav:1.8.0:beta6:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "B608EDD4-207A-41A7-A60D-496FDA8EAFEA"
},
{
"criteria": "cpe:2.3:a:getgrav:grav:1.8.0:beta7:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "AE1F2253-3EE0-4ADD-B8A5-C882A60FC626"
},
{
"criteria": "cpe:2.3:a:getgrav:grav:1.8.0:beta8:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "81D4C859-5560-42F1-ACD9-65210E523F28"
},
{
"criteria": "cpe:2.3:a:getgrav:grav:1.8.0:beta9:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "156707A7-9507-4AC1-9CD0-90E32836E9DF"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "security-advisories@github.com"
}