Impact
The vulnerability arises from the saveGlobalElements method in Vvveb’s admin controller, which concatenates an attacker‑controlled file path from the data-v-save-global POST parameter to the active theme directory without proper sanitization. This allows an authenticated user with the default Editor role and editor/* permissions to submit crafted HTML that causes the server to write arbitrary PHP code into any writable file outside the theme directory, including publicly accessible files. The resulting PHP payload executes in the web server context, giving the attacker persistent shell access and the ability to compromise the application’s confidentiality, integrity, and availability.
Affected Systems
This flaw affects Vvveb CMS versions from 1.0.0 through 1.0.8.5 distributed by givanz. Users running those versions should verify they are running the latest patched release (1.0.8.5 or later) or otherwise restrict the Editor role’s write permissions.
Risk and Exploitability
The CVSS score of 8.8 reflects the high impact of remote code execution, whereas the EPSS score of less than 1% indicates a very low but non‑zero likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog. Attackers need authenticated access with Editor privileges and must submit a crafted request to module=editor/editor&action=save. Once the malicious content is written to a web‑accessible PHP file, it is executed immediately, enabling the attacker to maintain long‑term persistence on the host.
OpenCVE Enrichment