CyberRota Analysis
AI-GeneratedA vulnerability in Vvveb CMS prior to version 1.0.8.6 allows authenticated admin-panel users with backup access to exploit a flawed central path sanitizer, enabling them to read and delete arbitrary files on the server. This could lead to the exposure of sensitive data, such as database credentials, and potentially allow attackers to take full control of the site. Organizations using affected versions should prioritize updating to the patched version to mitigate the risk of unauthorized access and data breaches.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
Vvveb is a powerful and easy to use CMS with page builder to build websites, blogs or ecommerce stores. Prior to version 1.0.8.6, a flawed central path sanitizer lets an authenticated admin-panel user who holds backup access (default role site_admin or higher) read and delete arbitrary files on a server. An attacker can recover database credentials from config/db.php, read host files such as /etc/passwd, and delete config/db.php to push a site back into install mode for a full takeover. This issue has been patched in version 1.0.8.6.