Grav Login Plugin: Unauthenticated Privilege Escalation via Missing Server-Side Validation of User Metadata Fields
The Grav Login plugin fails to validate user-supplied `groups` and `access` fields during registration, allowing unauthenticated attackers to self-register with administrative privileges when these fields are included in the allowed registration fields configuration.