Vvveb versions prior to 1.0.8.1 are affected by a critical code injection vulnerability in the installation endpoint where the subdir POST parameter is written unsanitized into the env.php configuration file, allowing attackers to inject arbitrary PHP code and achieve unauthenticated remote code execution. The vulnerability carries a CVSS score of 9.8 (Critical) due to its network-based attack vector, low complexity, and lack of required privileges or user interaction, resulting in complete compromise of confidentiality, integrity, and availability. While the CVE is listed as active on vulnerability tracking lists, the EPSS score of 0.00218 indicates relatively low exploit prevalence compared to other CVEs in circulation, suggesting limited current exploitation activity despite the vulnerability's severe risk profile.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 0, < 1.0.8.1CPE match | cpe:2.3:a:vvveb:vvveb:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.