PT-2025-43861 · Unknown · Givanz Vvveb
Huu1J
·
Published
2025-10-27
·
Updated
2025-11-07
·
CVE-2025-12203
CVSS v3.1
6.3
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L |
Name of the Vulnerable Software and Affected Versions
givanz Vvveb versions up to 1.0.7.3
Description
A weakness exists in givanz Vvveb related to path traversal. This issue affects the
sanitizeFileName function within the system/functions.php file of the Code Editor component. Manipulation of the File argument can lead to unauthorized access. The attack can be initiated remotely, and an exploit is publicly available.Recommendations
Apply the patch b0fa7ff74a3539c6d37000db152caad572e4c39b to resolve this issue.
Exploit
Fix
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Givanz Vvveb