PT-2025-31849 · Unknown · Givanz Vvveb

·

CVE-2025-8520

·

Published

2025-08-04

·

Updated

2025-08-04

CVSS v2.0

5.8

Medium

VectorAV:N/AC:L/Au:M/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions givanz Vvveb versions up to 1.0.5
Description A critical vulnerability exists in the Drag-and-Drop Editor component of givanz Vvveb. The vulnerability is due to server-side request forgery, which can be triggered by manipulating the url argument in the /vadmin123/?module=editor/editor API endpoint. The attack can be initiated remotely, and the exploit has been publicly disclosed.
Recommendations Upgrade to version 1.0.6.

Exploit

Fix

SSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-8520

Affected Products

Givanz Vvveb