Description


A critical vulnerability has been identified in givanz VvvebJs 1.7.2, which allows both Server-Side Request Forgery (SSRF) and arbitrary file reading. The vulnerability stems from improper handling of user-supplied URLs in the "file_get_contents" function within the "save.php" file.

Related CPE's


Vulnerable

Weaknesses


134c704f-9b21-4f2e-91b3-4a467353bcc0

Secondary

CWE-918

CVSS impact metrics


CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

9.1 · Critical

Information


Source identifier

[email protected]

Vulnerability status

Analyzed

Published

2025-12-29T20:15:40.423Z

3 weeks ago

Last modified

2026-01-07T14:50:45.963Z

2 weeks ago