Impact
The vulnerability is a server‑side request forgery that bypasses the CMS’s IPv4‑only validation routine, allowing an attacker to supply an IPv6 literal or a domain resolved only via AAAA records. The editor’s oEmbed proxy fetches the supplied URL server‑side and reflects the response body. An authenticated administrator (site_admin or higher) can thereby retrieve internal‑only services and cloud metadata, including IAM credentials, exposing sensitive information that could be leveraged for further compromise.
Affected Systems
The affected product is Vvveb.com CMS, all releases prior to 1.0.8.6. Users with administrator privileges on the site’s admin panel are at risk, while non‑privileged users cannot exploit this path.
Risk and Exploitability
The CVSS score of 7.6 indicates a high severity level. The EPSS score is currently unavailable, and the vulnerability is not listed in the CISA KEV catalog, suggesting limited public exploitation data. However, the requirement of an authenticated admin account means that attackers who obtain or guess valid credentials can execute the SSRF, potentially exfiltrating internal data or cloud identities. The risk is therefore moderate to high for systems with exposed admin panels and where internal services are not adequately protected.
OpenCVE Enrichment