CyberRota Analysis
AI-GeneratedVvveb CMS versions prior to 1.0.8.4 are vulnerable to unauthorized access, allowing low-privileged vendors to manage product questions associated with other vendors' products. This flaw can lead to exposure of sensitive question content, unauthorized modifications, and potential deletion of questions, compromising the integrity of product Q&A sections. Organizations using Vvveb should prioritize upgrading to version 1.0.8.4 to mitigate these risks.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
Vvveb is a powerful and easy to use CMS with page builder to build websites, blogs or ecommerce stores. Prior to 1.0.8.4, Vvveb backend product question operations allow a low-privileged Vendor to manage questions under another Vendor's products. The admin/sql/sqlite/product_question.sql queries accept a caller-controlled product_question_id and do not verify product_question.product_id against product.admin_id for the current admin_id. An attacker can read pending question content and moderation data, change question status, edit question content, or delete questions, manipulating product Q&A visibility and integrity. This issue is fixed in version 1.0.8.4.