Impact
Vvveb, a CMS for websites and e‑commerce, allows a low‑privileged vendor to view, list, edit, or delete digital assets belonging to other vendors because ownership checks on the digital_asset_id are missing. An attacker can therefore obtain private image or file metadata, change resource links, or cause irreversible data loss. The flaw is a classic instance of authorization bypass (CWE‑639) that directly compromises confidentiality, integrity, and availability of vendor‑owned content.
Affected Systems
The vulnerability affects all releases of the Vvveb CMS before version 1.0.8.4. The product is maintained by Givanz and is commonly deployed by individual vendors who publish their own digital assets. The fix is included in release 1.0.8.4 and later versions.
Risk and Exploitability
The CVSS score of 8.8 classifies the issue as high severity. EPSS information is not available, and the flaw has not yet been listed in the CISA KEV catalog, suggesting no mass exploitation has been observed. The likely attack vector is remote, performed by any authenticated vendor user via the CMS administrative interface. An attacker can exploit the uncontrolled digital_asset_id parameter to enumerate other vendors’ assets, read sensitive metadata, edit or delete records, and thereby compromise the integrity and availability of the affected assets. The absence of a containment boundary means the entire digital‑asset management service is at risk for a single vulnerable vendor account.
OpenCVE Enrichment