PT-2026-38220 · Vvveb · Vvveb
Basant Kumar
+2
·
Published
2026-05-06
·
Updated
2026-05-06
·
CVE-2026-41931
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Vvveb versions prior to 1.0.8.2
Description
An information disclosure issue allows unauthenticated attackers to obtain sensitive server information by triggering unhandled exceptions in the password-reset module. By accessing the admin password-reset endpoint, a fatal error is triggered due to a missing namespace import. This exposes the absolute server file path, internal class namespaces, line numbers, and source code excerpts through the debug exception handler.
Recommendations
Update to version 1.0.8.2 or later.
Exploit
Fix
Generation of Error Message Containing Sensitive Information
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Vvveb