PT-2025-43861 · Unknown · Givanz Vvveb

Huu1J

·

Published

2025-10-27

·

Updated

2025-11-07

·

CVE-2025-12203

CVSS v3.1

6.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions givanz Vvveb versions up to 1.0.7.3
Description A weakness exists in givanz Vvveb related to path traversal. This issue affects the sanitizeFileName function within the system/functions.php file of the Code Editor component. Manipulation of the File argument can lead to unauthorized access. The attack can be initiated remotely, and an exploit is publicly available.
Recommendations Apply the patch b0fa7ff74a3539c6d37000db152caad572e4c39b to resolve this issue.

Exploit

Fix

Path traversal

Weakness Enumeration

Related Identifiers

CVE-2025-12203

Affected Products

Givanz Vvveb