PT-2025-35409 · Unknown · Givanz Vvveb

Andyp138

·

Published

2025-08-31

·

Updated

2025-09-05

·

CVE-2025-9728

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions givanz Vvveb version 1.0.7.2
Description A security vulnerability exists in givanz Vvveb 1.0.7.2, affecting an unknown part of the app/template/user/login.tpl file. Manipulation of the Email/Password argument can lead to cross-site scripting. The attack can be executed remotely.
Recommendations Apply the patch bbd4c42c66ab818142240348173a669d1d2537fe to resolve this issue.

Exploit

Fix

XSS

Code Injection

Weakness Enumeration

Related Identifiers

CVE-2025-9728

Affected Products

Givanz Vvveb