PT-2026-95142 · Vvveb · Vvveb
CVSS v4.0
8.4
High
| Vector | AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:H/SI:H/SA:N |
Name of the Vulnerable Software and Affected Versions
Vvveb versions prior to 1.0.8.5
Description
The
oEmbedProxy() handler in admin/controller/editor/editor.php accepts an attacker-controlled url parameter and passes it to getUrl(). The validateUrl() function in system/functions.php only checks the hostname string and fails to validate resolved addresses. An authenticated admin-panel user with editor/* permissions can use the endpoint '/admin/index.php?module=editor/editor&action=oEmbedProxy' with a dotted hostname or normalized loopback form that resolves to a private, loopback, link-local, or reserved address. This causes the server to issue an HTTP or HTTPS request and return the response body, potentially disclosing internal service responses, cloud instance metadata, and associated credentials. This is a Server-Side Request Forgery (SSRF) issue, where the server is tricked into making requests to internal resources. Because the action uses GET, no CSRF token is required.Recommendations
Update to version 1.0.8.5.
Exploit
Fix
SSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Vvveb