{"id":"CVE-2025-66301","aliases":["GHSA-v8x2-fjv7-8hjh"],"url":"https://o3.security/vulnerability/CVE-2025-66301","summary":"Grav ihas Broken Access Control which allows an Editor to modify the page's YAML Frontmatter to alter form processing actions","details":"### Summary\nDue to a broken access control vulnerability in the `/admin/pages/{page_name}` endpoint, an editor ( user with full permissions to pages ) can change the functionality of a form after submission.\n\n### Details\nDue to improper authorization checks when modifying critical fields on a POST request to `/admin/pages/{page_name}`, an editor with only permissions to change basic content on the form is now able to change the functioning of the form through modifying the content of the `data[_json][header][form]` which is the YAML frontmatter which includes the `process` section which dictates what happens after a user submits the form which include some important actions that could lead to further vulnerabilities.\n\n### PoC\n\n- Have Admin and Form plugins installed\n- Connect to panel as admin, create user and give him permission for pages all\n- Now connect as that user and notice you cant edit any process field in the panel\n- Change anything in the content of the form and save\n- Intercept the request:\n![image](https://github.com/user-attachments/assets/a66767d9-648e-45b5-9031-4a15bee3072a)\n\n- Now modify the field `data[_json][header][form] with the following payload URL-encoded not like this:\n```\n{\"name\":\"ssti-test 2\",\"fields\":{\"name\":{\"type\":\"text\",\"label\":\"Name\",\"required\":true}},\"buttons\":{\"submit\":{\"type\":\"submit\",\"value\":\"Submit\"}},\"process\":[{\"message\":\"{{ evaluate_twig(form.value('name')) }}\"}]}\n```\n\n- Change the field and forward it:\n![image](https://github.com/user-attachments/assets/dd5f95d7-c61f-4fc0-9e9a-e67825f20aea)\n\nRequest goes through and changes have been made to the form.\n![image](https://github.com/user-attachments/assets/42a77e10-571b-43a2-8410-14d82dba28e5)\n\n### Impact\n\n- Attacker can modify submission logic of the form which leads to changing redirect value, email sending, changing template, breaking out of the Twig sandbox potentially executing code...\n\n### Fix recommendation\n\n- Implement proper authorization checks to such requests especially when it contains fields user shouldn't be able to modify based on his role.","published":"2025-12-01T21:30:43.359Z","modified":"2026-08-12T03:51:31.902244205Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Packagist","name":"getgrav/grav","fixedVersion":"1.8.0-beta.27"}],"fix":null,"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/66xxx/CVE-2025-66301.json"},{"type":"ADVISORY","url":"https://github.com/getgrav/grav/security/advisories/GHSA-v8x2-fjv7-8hjh"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-66301"},{"type":"PACKAGE","url":"https://github.com/getgrav/grav"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T03:51:31.902244205Z"}}