Vvveb · Vvveb · CVE-2026-54507
**Name of the Vulnerable Software and Affected Versions**
Vvveb versions prior to 1.0.8.5
**Description**
The `oEmbedProxy()` handler in admin/controller/editor/editor.php accepts an attacker-controlled `url` parameter and passes it to `getUrl()`. The `validateUrl()` function in system/functions.php only checks the hostname string and fails to validate resolved addresses. An authenticated admin-panel user with editor/* permissions can use the endpoint '/admin/index.php?module=editor/editor&action=oEmbedProxy' with a dotted hostname or normalized loopback form that resolves to a private, loopback, link-local, or reserved address. This causes the server to issue an HTTP or HTTPS request and return the response body, potentially disclosing internal service responses, cloud instance metadata, and associated credentials. This is a Server-Side Request Forgery (SSRF) issue, where the server is tricked into making requests to internal resources. Because the action uses GET, no CSRF token is required.
**Recommendations**
Update to version 1.0.8.5.