CVE-2025-8517
MEDIUMgivanz Vvveb <1.0.6.1 - Info Disclosure
Title source: llmDescription
A vulnerability was detected in givanz Vvveb 1.0.6.1. Impacted is an unknown function. The manipulation results in session fixiation. The attack can be launched remotely. The exploit is now public and may be used. Upgrading to version 1.0.7 is recommended to address this issue. The patch is identified as d4b1e030066417b77d15b4ac505eed5ae7bf2c5e. You should upgrade the affected component.
Exploits (1)
nomisec
WRITEUP
by helloandrewpaul · poc
https://github.com/helloandrewpaul/Session-Fixation-in-Vvveb-CMS-v1.0.6.1
References (9)
Scores
CVSS v3
6.3
EPSS
0.0019
EPSS Percentile
41.0%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
CISA SSVC
Vulnrichment
Exploitation
poc
Automatable
no
Technical Impact
partial
Details
CWE
CWE-384
Status
published
Products (1)
vvveb/vvveb
< 1.0.7
Published
Aug 04, 2025
Tracked Since
Feb 18, 2026