Impact
The Vvveb CMS backend product controller accepts a caller‑controlled product_id parameter for duplicate and delete actions without ensuring the vendor owns that product. This flaw, classified as CWE‑639, allows a low‑privileged vendor to read, duplicate, or delete products belonging to other vendors. An attacker can thereby expose commercial information, create unauthorized copies of catalog items, pollute the store inventory and cause data loss or business disruption.
Affected Systems
The vulnerability affects all versions of the Vvveb CMS released by givanz prior to version 1.0.8.4. The affected product is the Vvveb Content Management System, where vendor‑level accounts are authenticated through the admin interface.
Risk and Exploitability
With a CVSS score of 8.8 the flaw is considered High severity. The exploit does not require elevated privileges beyond a legitimate vendor account; any vendor can transmit a malicious product_id to bypass authorization checks. No EPSS score is available, and the vulnerability is not listed in CISA’s KEV catalog, suggesting it is not yet widely exploited in the wild. However, given the ease of the attack, the potential impact is significant and the risk remains high until a patch is applied.
OpenCVE Enrichment