VulnerabilityAnalyzed
CVE-2025-8517
A vulnerability was detected in givanz Vvveb 1.0.6.1.
LOW 2.1EPSS 0.68%
Does this matter?
Lower severity and a low EPSS score (0.68%). Track it; it rarely justifies an emergency change on its own.
Description
A vulnerability was detected in givanz Vvveb 1.0.6.1. Impacted is an unknown function. The manipulation results in session fixiation. The attack can be launched remotely. The exploit is now public and may be used. Upgrading to version 1.0.7 is recommended to address this issue. The patch is identified as d4b1e030066417b77d15b4ac505eed5ae7bf2c5e. You should upgrade the affected component.
- CVSS 4.0
- 2.1 LOWCVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/M
- EPSS
- 0.68% probability · 50th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-384
- Affected
- vvveb/vvveb
- Source
- cna@vuldb.com
References
- https://github.com/givanz/Vvveb/commit/d4b1e030066417b77d15b4ac505eed5ae7bf2c5ePatch
- https://github.com/givanz/Vvveb/issues/312Exploit, Issue Tracking, Mitigation
- https://github.com/givanz/Vvveb/issues/312#issuecomment-2977995664Issue Tracking
- https://github.com/givanz/Vvveb/releases/tag/1.0.7Release Notes
- https://github.com/kwerty138/Session-Fixation-in-Vvveb-CMS-v1.0.6.1Exploit, Mitigation
- https://vuldb.com/?ctiid.318643Permissions Required, VDB Entry
- https://vuldb.com/?id.318643Third Party Advisory, VDB Entry
- https://vuldb.com/?submit.623135Third Party Advisory, VDB Entry
- https://github.com/givanz/Vvveb/issues/312Exploit, Issue Tracking, Mitigation
- https://github.com/helloandrewpaul/Session-Fixation-in-Vvveb-CMS-v1.0.6.1Exploit, Mitigation
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.