givanz Vvveb edit.tpl cross site scripting
Published Aug 14, 2025
5.1
MEDIUMCVSS 4.0
EPSS 0.29%
Description
A vulnerability was identified in givanz Vvveb up to 1.0.5. This affects an unknown part of the file admin/template/content/edit.tpl. The manipulation of the argument slug leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 1.0.6 is able to address this issue. The patch is named 84c11d69df8452dc378feecd17e2a62ac10dac66. It is recommended to upgrade the affected component.
Affected products
-
- Version 1.0.0StatusaffectedConstraints-
- Version 1.0.1StatusaffectedConstraints-
- Version 1.0.2StatusaffectedConstraints-
- Version 1.0.3StatusaffectedConstraints-
- Version 1.0.4StatusaffectedConstraints-
- Version 1.0.5StatusaffectedConstraints-
- Version 1.0.6StatusunaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (8)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2025-24938 Advisory
- https://gist.github.com/0xHamy/b2674eeffd1f73af96d29f152c47bcbd exploitProduct
- https://github.com/givanz/Vvveb/commit/84c11d69df8452dc378feecd17e2a62ac10dac66 patch
- https://github.com/givanz/Vvveb/releases/tag/1.0.6 patchRelease Notes
- https://hkohi.ca/vulnerability/6 relatedExploitThird Party Advisory
- https://vuldb.com/?ctiid.319971 signaturepermissions-requiredPermissions RequiredVDB Entry
- https://vuldb.com/?id.319971 vdb-entrytechnical-descriptionThird Party AdvisoryVDB Entry
- https://vuldb.com/?submit.628296 third-party-advisoryThird Party AdvisoryVDB Entry
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2025-24938 | Advisory | |
| https://gist.github.com/0xHamy/b2674eeffd1f73af96d29f152c47bcbd | exploitProduct | |
| https://github.com/givanz/Vvveb/commit/84c11d69df8452dc378feecd17e2a62ac10dac66 | patch | |
| https://github.com/givanz/Vvveb/releases/tag/1.0.6 | patchRelease Notes | |
| https://hkohi.ca/vulnerability/6 | relatedExploitThird Party Advisory | |
| https://vuldb.com/?ctiid.319971 | signaturepermissions-requiredPermissions RequiredVDB Entry | |
| https://vuldb.com/?id.319971 | vdb-entrytechnical-descriptionThird Party AdvisoryVDB Entry | |
| https://vuldb.com/?submit.628296 | third-party-advisoryThird Party AdvisoryVDB Entry |
Change history (0)
No recorded changes yet.