PT-2026-77186 · Vvveb · Vvveb
CVE-2026-49221
·
Published
2026-08-18
·
Updated
2026-08-18
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Vvveb versions prior to 1.0.8.4
Description
Backend digital asset operations allow a low-privileged Vendor to access digital assets linked to other Vendors' products. The controllers 'admin/controller/product/digital-asset.php' and 'admin/controller/product/digital-assets.php', along with the 'admin/sql/sqlite/digital asset.sql' data queries, use a caller-controlled
digital asset id without consistently enforcing the admin id ownership boundary. This allows an attacker to list assets, read asset names and file metadata, edit asset metadata, or delete asset records, potentially disclosing private product metadata, corrupting resource links, and causing data loss.Recommendations
Update to version 1.0.8.4.
Exploit
Fix
IDOR
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Vvveb