PT-2026-38220 · Vvveb · Vvveb

Basant Kumar

+2

·

Published

2026-05-06

·

Updated

2026-05-06

·

CVE-2026-41931

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Vvveb versions prior to 1.0.8.2
Description An information disclosure issue allows unauthenticated attackers to obtain sensitive server information by triggering unhandled exceptions in the password-reset module. By accessing the admin password-reset endpoint, a fatal error is triggered due to a missing namespace import. This exposes the absolute server file path, internal class namespaces, line numbers, and source code excerpts through the debug exception handler.
Recommendations Update to version 1.0.8.2 or later.

Exploit

Fix

Generation of Error Message Containing Sensitive Information

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-41931

Affected Products

Vvveb