CVE-2026-54612
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Summary
Vvveb is a powerful and easy to use CMS with page builder to build websites, blogs or ecommerce stores. From 1.0.0 until 1.0.8.5, saveGlobalElements() in admin/controller/editor/global-trait.php concatenates the attacker-controlled file portion of data-v-save-global to the active theme directory before loadHTMLFile() and file_put_contents() operate on it. An authenticated user with the default Editor role and editor/* permission can submit crafted HTML to module=editor/editor&action=save and traverse to an existing writable PHP file outside the theme directory. If the target is web-accessible, editor-controlled PHP content executes in the web server context; a shipped public/vadmin/index.php entrypoint can be used as an execution trampoline rather than requiring a test-only file. This can permit persistent webshell placement and compromise application confidentiality, integrity, and availability. This issue is fixed in version 1.0.8.5.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| givanz | Vvveb | >= 1.0.0, < 1.0.8.5 | affected |
Weaknesses
- CWE-22: CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
- CWE-94: CWE-94: Improper Control of Generation of Code ('Code Injection')
References
- https://github.com/givanz/Vvveb/security/advisories/GHSA-c3v9-3xrq-pvqv
- https://github.com/givanz/Vvveb/commit/c8fef41ad8651d348050c513451755ab8882b97e
- https://github.com/givanz/Vvveb/releases/tag/1.0.8.5
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.