VvvebJs Directory Traversal Vulnerability

Vulnerability

A directory traversal vulnerability has been identified in VvvebJs version 1.7.2. This issue allows attackers to read arbitrary directories by exploiting the 'scan.php' file.

Impact

Exploitation of this vulnerability could lead to unauthorized access to sensitive files and directories on the server.

Reproduction

To reproduce this vulnerability, send a POST request to 'scan.php' with a 'mediaPath' parameter that includes directory traversal sequences. This will allow access to files outside the intended directory, such as system files.

Added: Dec 29, 2025, 9:20 PM
Updated: Dec 29, 2025, 9:20 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
3.3
exploitability
6.0
remediation
0.0
relevance
1.7
threat
6.4
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.