PT-2025-35409 · Unknown · Givanz Vvveb

·

CVE-2025-9728

·

Published

2025-08-31

·

Updated

2025-09-05

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions givanz Vvveb version 1.0.7.2
Description A security vulnerability exists in givanz Vvveb 1.0.7.2, affecting an unknown part of the app/template/user/login.tpl file. Manipulation of the Email/Password argument can lead to cross-site scripting. The attack can be executed remotely.
Recommendations Apply the patch bbd4c42c66ab818142240348173a669d1d2537fe to resolve this issue.

Exploit

Fix

XSS

Code Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-9728

Affected Products

Givanz Vvveb