Product
An improper authorization vulnerability in the Grav Flex Objects plugin API allows an authenticated user with limited administrative privileges to escalate their access and gain full site control via unauthorized password resets or group privilege modification.