top of page
perceptive_background_267k.jpg

Vvveb before version 1.0.8.2 contains an authenticated remote code execution vulnerability in the admin code editor that allows low-privilege authenticated user…

Published:

5 mei 2026 om 22:00:00

Alert date:

6 mei 2026 om 20:01:39

Source:

nvd.nist.gov

Click to open the original link from this advisory

Web Technologies

Vvveb before version 1.0.8.2 contains an authenticated remote code execution vulnerability in the admin code editor. The vulnerability allows low-privilege authenticated users (editor, author, contributor, or site_admin roles) to execute arbitrary code by exploiting insufficient file extension restrictions. Attackers can write a malicious .htaccess file to map arbitrary extensions to the PHP handler, then upload PHP code with that extension. This can lead to unauthenticated remote code execution when the malicious file is accessed via HTTP. The vulnerability affects the admin code editor component and has been addressed in version 1.0.8.2.

Technical details

Mitigation steps:

Affected products:

Vvveb

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Deze website toont informatie afkomstig van externe bronnen; Perceptive aanvaardt geen verantwoordelijkheid voor de juistheid, volledigheid of actualiteit van deze informatie.

bottom of page