Impact
The vulnerability is a stored cross‑site scripting flaw caused by the HTML sanitizer overlooking event‑handler attributes when a tag contains a quoted greater‑than character. The flaw allows a low‑privilege content author, such as an author or contributor, to embed JavaScript that executes in the browsers of all site visitors and any site administrator who views or previews the affected content. Execution of the script can lead to hijacking of an administrator account if the attacker can conduct account takeover or other privileged actions. This defect is classified as CWE‑79.
Affected Systems
Vvveb CMS produced by Givanz, versions earlier than 1.0.8.6. Any installation of Vvveb that has not been upgraded to 1.0.8.6 or later is vulnerable.
Risk and Exploitability
The CVSS score of 8.7 indicates high severity. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog. The attack vector is via content creation by users with author or contributor roles, who can store malicious payloads that bypass the sanitization process. The stored payload is then rendered as part of page content, causing arbitrary script execution in the browsers of every visitor and administrator. This can directly lead to privilege escalation and account takeover.
OpenCVE Enrichment