Impact
The vulnerability allows an authenticated admin with editor permission to trigger GET requests to arbitrary URLs through the oEmbedProxy endpoint. The request validation only checks hostname strings and does not resolve the IP address, enabling the server to fetch content from private, loopback, link‑local, or reserved addresses. This can expose internal service responses or cloud instance metadata that may contain credentials. The flaw results in high‑severity information disclosure rather than arbitrary code execution, but it is critical because it leaks data to anyone who has administrative access.
Affected Systems
Vvveb content management systems from givanz, versions earlier than 1.0.8.5, are affected. Any deployment running those versions, when accessed by an authenticated admin with editor privileges, can exploit the endpoint. Storefront users and anonymous visitors cannot invoke the endpoint because it lacks a CSRF token and requires admin authentication.
Risk and Exploitability
The CVSS score of 8.4 indicates a high severity level. The EPSS score of less than 1% suggests a low probability of exploitation in the wild, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is an authenticated admin exploiting the GET‑based oEmbedProxy action. Exploitation requires only normal admin credentials and an ability to construct a URL that resolves to a privileged address; no additional network access is required beyond the server’s outbound connections.
OpenCVE Enrichment