PT-2026-95142 · Vvveb · Vvveb

·

CVE-2026-54507

·

Published

2026-09-17

·

Updated

2026-09-17

CVSS v4.0

8.4

High

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:H/SI:H/SA:N
Name of the Vulnerable Software and Affected Versions Vvveb versions prior to 1.0.8.5
Description The oEmbedProxy() handler in admin/controller/editor/editor.php accepts an attacker-controlled url parameter and passes it to getUrl(). The validateUrl() function in system/functions.php only checks the hostname string and fails to validate resolved addresses. An authenticated admin-panel user with editor/* permissions can use the endpoint '/admin/index.php?module=editor/editor&action=oEmbedProxy' with a dotted hostname or normalized loopback form that resolves to a private, loopback, link-local, or reserved address. This causes the server to issue an HTTP or HTTPS request and return the response body, potentially disclosing internal service responses, cloud instance metadata, and associated credentials. This is a Server-Side Request Forgery (SSRF) issue, where the server is tricked into making requests to internal resources. Because the action uses GET, no CSRF token is required.
Recommendations Update to version 1.0.8.5.

Exploit

Fix

SSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-54507
GHSA-XXP7-59P2-4JR8

Affected Products

Vvveb