PT-2026-95145 · Vvveb · Vvveb
CVSS v3.1
5.4
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Vvveb versions prior to 1.0.8.5
Description
An issue exists where the
getThemeFolder() function in admin/controller/editor/revisions.php returns the theme parameter without proper sanitization. The backupFolder() function then concatenates this parameter beneath DIR THEMES before the editor/revisions/load or editor/revisions/delete endpoints operate on a .html file. While sanitizeBackupFileName() removes traversal characters from the file parameter, it fails to protect the theme directory component. An authenticated user with the Editor role and editor/* permission can use traversal sequences to redirect file get contents() or unlink() to backup subdirectories outside the web root. This requires a valid admin session and CSRF token. The impact includes the disclosure of sensitive exported site content (limited to .html files in backup directories) or the removal of backup data, provided the system has filesystem write permissions.Recommendations
Update to version 1.0.8.5.
Exploit
Fix
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Vvveb