Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2025-8520

Опубликовано: 04 авг. 2025
Источник: nvd
CVSS3: 4.7
CVSS2: 5.8
EPSS Низкий

Описание

A vulnerability classified as critical was found in givanz Vvveb up to 1.0.5. This vulnerability affects unknown code of the file /vadmin123/?module=editor/editor of the component Drag-and-Drop Editor. The manipulation of the argument url leads to server-side request forgery. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 1.0.6 is able to address this issue. The patch is identified as f684f3e374d04db715730fc4796e102f5ebcacb2. It is recommended to upgrade the affected component.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:vvveb:vvveb:*:*:*:*:*:*:*:*
Версия до 1.0.6 (исключая)

EPSS

Процентиль: 25%
0.00086
Низкий

4.7 Medium

CVSS3

5.8 Medium

CVSS2

Дефекты

CWE-918

Связанные уязвимости

CVSS3: 4.7
github
6 месяцев назад

A vulnerability classified as critical was found in givanz Vvveb up to 1.0.5. This vulnerability affects unknown code of the file /vadmin123/?module=editor/editor of the component Drag-and-Drop Editor. The manipulation of the argument url leads to server-side request forgery. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 1.0.6 is able to address this issue. The patch is identified as f684f3e374d04db715730fc4796e102f5ebcacb2. It is recommended to upgrade the affected component.

EPSS

Процентиль: 25%
0.00086
Низкий

4.7 Medium

CVSS3

5.8 Medium

CVSS2

Дефекты

CWE-918