Product
Grav CMS versions 1.7.x and 2.0.0 through 2.0.24 are vulnerable to session hijacking due to an improperly restricted get_cookie() function within the Twig rendering engine.