← volver
CVE-2026-41931

Vvveb < 1.0.8.2 Information Disclosure via Debug Exception Handler

CVSS 6.9 MEDIUMEPSS 0.2%CWE-1188CWE-209
Vexday Risk Score
13Bajo
Decisión SSVC (CISA)
Track
Sin señal de explotación → monitorear
CVSS 6.9EPSS 0.2%KEV nãoPoC Nuclei Metasploit Patch referenciado
Ciclo de vida
06 may 2026Publicada en NVD
Recomendación: Monitorear — sin señal de explotación por ahora.
Vvveb before version 1.0.8.2 contains an information disclosure vulnerability that allows unauthenticated attackers to obtain sensitive server information by triggering unhandled exceptions in the password-reset module. Attackers can access the admin password-reset endpoint to trigger a fatal error caused by a missing namespace import, which exposes the absolute server file path, internal class namespaces, line numbers, and source code excerpts through the debug exception handler rendered to unauthenticated requests.
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
Productos afectados
givanz · Vvveb

¿Quieres saber si tu infraestructura está expuesta a esto?

Hablar con TrueHacking →