CVE-2025-8518
givanz Vvveb Code Editor code.php save code injection
Vexday Risk Score
28Low
SSVC decision (CISA)
Attend
PoC available → attend closely
CVSS 5.1EPSS 1.3%KEV nãoPoC —Nuclei —Metasploit simPatch referenciado
Lifecycle
10 Jan 2025Metasploit module available
04 Aug 2025Published on NVD
Recommendation: Plan a near-term fix — a public PoC already exists.
A vulnerability was found in givanz Vvveb 1.0.5. It has been rated as critical. Affected by this issue is the function Save of the file admin/controller/editor/code.php of the component Code Editor. The manipulation leads to code injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 1.0.6 is able to address this issue. The name of the patch is f684f3e374d04db715730fc4796e102f5ebcacb2. It is recommended to upgrade the affected component.
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P
Affected products
givanz · VvvebWant to know if your infrastructure is exposed to this?
Talk to TrueHacking →References
https://gist.github.com/0xHamy/f16fb399f8dd3a973acadc18fa07b1cbhttps://github.com/givanz/Vvveb/commit/f684f3e374d04db715730fc4796e102f5ebcacb2https://github.com/givanz/Vvveb/releases/tag/1.0.6https://hkohi.ca/vulnerability/8https://vuldb.com/?ctiid.318644https://vuldb.com/?id.318644https://vuldb.com/?submit.624971