Impact
Vvveb CMS’s user profile bio field is used to store data that is later rendered on public, administrative, and comment pages. The application’s sanitizeHTML() function fails to strip solidus‑prefixed event‑handler attributes and nested forbidden tags, allowing attacker‑controlled JavaScript to persist in the bio. When unauthenticated visitors, administrators, or other users access a profile or view comments, the injected code executes in the victim’s browser. This flaw exposes the victim’s browser session, permits account‑taking actions within the same context, and enables defacement or phishing attacks.
Affected Systems
The vulnerability affects the Vvveb CMS from the vendor givanz. Any installation running a version earlier than 1.0.8.5 is susceptible. The fix is included in the 1.0.8.5 release and later.
Risk and Exploitability
The CVSS score of 7.6 indicates high severity, but the EPSS of less than 1% suggests a low likelihood of exploitation at present. The flaw is currently not listed in the CISA KEV catalog. Attackers would need to create or inject a malicious bio as a user with Author role or higher, and then rely on victims to view the affected profile or comment page, which can be achieved automatically via contextual link clicks. The impact is thus confined to browsers rendering the content, with potential for session hijacking and malicious page interaction.
OpenCVE Enrichment