漏洞情报聚合

CVE-2026-56707 - Grav Flex Objects plugin versions 1.4.0 through 1.4.7 contain an authorization bypass vulnerability in the flex-objects shortcode that allows users with page-edit access to render any registered Flex collection without permission checks. Attackers can place the shortcode in published pages to expose sensitive directory contents including user account information, bypassing the authorize ACL enforced in the admin panel. - 漏洞详情

漏洞编号:CVE-2026-56707

风险等级:高危

漏洞来源:CVE

CVE 编号:CVE-2026-56707

CNNVD 编号:-

厂商/产品:- / -

影响范围:-

CWE:CWE-862

发布/更新时间:2026-08-25 / 2026-08-27

漏洞描述

Grav Flex Objects plugin versions 1.4.0 through 1.4.7 contain an authorization bypass vulnerability in the flex-objects shortcode that allows users with page-edit access to render any registered Flex collection without permission checks. Attackers can place the shortcode in published pages to expose sensitive directory contents including user account information, bypassing the authorize ACL enforced in the admin panel.

相关链接

相关漏洞

« 返回首页