Product
An authentication bypass vulnerability in the Grav CMS Comments plugin through version 1.2.10 allows unauthenticated attackers to exfiltrate comment data, including emails and server paths, via an improperly secured admin handler.