CVE-2025-8517

MEDIUM

givanz Vvveb <1.0.6.1 - Info Disclosure

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2025-8517. PoCs published by helloandrewpaul.

AI-analyzed exploit summary This repository provides a detailed technical analysis of a session fixation vulnerability (CVE-2025-8517) in Vvveb CMS v1.0.6.1, including root cause, attack vectors, and proof-of-concept steps. It highlights the failure to regenerate session IDs upon authentication and the acceptance of arbitrary session IDs.

Description

A vulnerability was detected in givanz Vvveb 1.0.6.1. Impacted is an unknown function. The manipulation results in session fixiation. The attack can be launched remotely. The exploit is now public and may be used. Upgrading to version 1.0.7 is recommended to address this issue. The patch is identified as d4b1e030066417b77d15b4ac505eed5ae7bf2c5e. You should upgrade the affected component.

Exploits (1)

nomisec WRITEUP
by helloandrewpaul · poc
https://github.com/helloandrewpaul/Session-Fixation-in-Vvveb-CMS-v1.0.6.1

This repository provides a detailed technical analysis of a session fixation vulnerability (CVE-2025-8517) in Vvveb CMS v1.0.6.1, including root cause, attack vectors, and proof-of-concept steps. It highlights the failure to regenerate session IDs upon authentication and the acceptance of arbitrary session IDs.

Classification
Writeup 100%
Attack Type
Auth Bypass
Complexity
Trivial
Reliability
Reliable
Target: Vvveb CMS v1.0.6.1
No auth needed
Prerequisites: Access to the victim's browser to set a cookie · Victim must log in after the cookie is set
devstral-2 · analyzed Feb 18, 2026 Full analysis →

References (9)

Core 9
Core References
Third Party Advisory, VDB Entry vdb-entry technical-description
https://vuldb.com/?id.318643
Permissions Required, VDB Entry signature permissions-required
https://vuldb.com/?ctiid.318643
Third Party Advisory, VDB Entry third-party-advisory
https://vuldb.com/?submit.623135
Exploit, Issue Tracking, Mitigation issue-tracking
https://github.com/givanz/Vvveb/issues/312

Scores

CVSS v3 6.3
EPSS 0.0064
EPSS Percentile 45.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-384
Status published
Products (1)
vvveb/vvveb < 1.0.7
Published Aug 04, 2025
Tracked Since Feb 18, 2026