CyberRota Analysis
AI-GeneratedVvveb CMS versions prior to 1.0.8.4 are vulnerable to unauthorized access in the product review management system, allowing low-privileged vendors to manipulate reviews associated with other vendors' products. This vulnerability can lead to the exposure of sensitive review information, as well as the ability to alter or delete reviews, compromising the integrity of product visibility and ratings. Organizations using Vvveb should prioritize upgrading to version 1.0.8.4 to mitigate these risks.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
Vvveb is a powerful and easy to use CMS with page builder to build websites, blogs or ecommerce stores. Prior to 1.0.8.4, Vvveb backend product review operations allow a low-privileged Vendor to manage reviews under another Vendor's products. The admin/sql/sqlite/product_review.sql queries accept a caller-controlled product_review_id and do not verify product_review.product_id against product.admin_id for the current admin_id. An attacker can read pending review content, ratings, author information, and moderation state, change review status, edit review content, or delete reviews, manipulating product review visibility and integrity. This issue is fixed in version 1.0.8.4.