CVE-2025-8517

MEDIUM

givanz Vvveb <1.0.6.1 - Info Disclosure

Title source: llm

Description

A vulnerability was detected in givanz Vvveb 1.0.6.1. Impacted is an unknown function. The manipulation results in session fixiation. The attack can be launched remotely. The exploit is now public and may be used. Upgrading to version 1.0.7 is recommended to address this issue. The patch is identified as d4b1e030066417b77d15b4ac505eed5ae7bf2c5e. You should upgrade the affected component.

Exploits (1)

nomisec WRITEUP
by helloandrewpaul · poc
https://github.com/helloandrewpaul/Session-Fixation-in-Vvveb-CMS-v1.0.6.1

Scores

CVSS v3 6.3
EPSS 0.0019
EPSS Percentile 41.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-384
Status published
Products (1)
vvveb/vvveb < 1.0.7
Published Aug 04, 2025
Tracked Since Feb 18, 2026