CVE-2025-8519 is an information disclosure vulnerability affecting givanz Vvveb versions up to 1.0.5, specifically within the Drag-and-Drop Editor component. This low-severity vulnerability (CVSS 2.7) allows a remote attacker with high privileges to disclose information by manipulating the 'url' argument in the /vadmin123/index.php?module=editor/editor file. While a public exploit exists, there is no evidence of active exploitation, and it lacks coverage in common exploit frameworks or significant community discussion. Upgrading to Vvveb version 1.0.6 is recommended to remediate this issue.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.0.6CPE matchmatch criteria | cpe:2.3:a:vvveb:vvveb:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.0 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.