Back

MEDIUM

givanz Vvveb login.tpl cross site scripting

Published Aug 31, 2025

Description

A security vulnerability has been detected in givanz Vvveb 1.0.7.2. This affects an unknown part of the file app/template/user/login.tpl. Such manipulation of the argument Email/Password leads to cross site scripting. The attack can be executed remotely. The name of the patch is bbd4c42c66ab818142240348173a669d1d2537fe. Applying a patch is advised to resolve this issue.

Affected products

Remediation

No remediation recorded yet.

References (7)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner VulDB
Published Aug 31, 2025
Updated Sep 2, 2025
Reserved Aug 30, 2025
CISA Vulnrichment
Updated Sep 2, 2025
NVD
Status Analyzed
Modified Jun 17, 2026
Red Hat
Severity n/a
Public date n/a
ENISA EUVD
Assigner VulDB
Published Aug 31, 2025
Updated Sep 2, 2025
Exploited since n/a
EUVD-2025-28882