CVE-2025-9728
MEDIUMVvveb 1.0.7.2 - Cross-Site Scripting via Email/Password Argument
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2025-9728. PoCs published by helloandrewpaul.
AI-analyzed exploit summary This repository provides a detailed technical analysis of a reflected XSS vulnerability in Vvveb CMS v1.0.7.2, including root cause analysis, proof-of-concept payloads, and mitigation recommendations. The vulnerability allows script injection via the email and password fields due to lack of output encoding.
Description
A security vulnerability has been detected in givanz Vvveb 1.0.7.2. This affects an unknown part of the file app/template/user/login.tpl. Such manipulation of the argument Email/Password leads to cross site scripting. The attack can be executed remotely. The name of the patch is bbd4c42c66ab818142240348173a669d1d2537fe. Applying a patch is advised to resolve this issue.
Exploits (1)
This repository provides a detailed technical analysis of a reflected XSS vulnerability in Vvveb CMS v1.0.7.2, including root cause analysis, proof-of-concept payloads, and mitigation recommendations. The vulnerability allows script injection via the email and password fields due to lack of output encoding.
References (6)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N