CyberRota Analysis
AI-GeneratedThe Vvveb CMS prior to version 1.0.8.4 is vulnerable due to improper access controls in its backend product operations, allowing low-privileged users to manipulate products owned by other vendors. This flaw can lead to unauthorized access to sensitive commercial information, duplication or deletion of products, and potential disruption of business operations. Organizations using Vvveb should prioritize upgrading to the latest version to mitigate these risks.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
Vvveb is a powerful and easy to use CMS with page builder to build websites, blogs or ecommerce stores. Prior to 1.0.8.4, Vvveb backend product operations allow a low-privileged Vendor to access products owned by another Vendor. The admin/controller/product/products.php controller accepts a caller-controlled product_id for duplicate and delete actions, and admin/sql/sqlite/product.sql loads and mutates products without consistently applying the current admin_id when view_other_products or edit_other_products is absent. An attacker can read product details, duplicate products, or delete products and related catalog data, exposing commercial information and causing unauthorized copies, catalog pollution, data loss, or business disruption. This issue is fixed in version 1.0.8.4.