givanz VvvebJs
cpe:2.3:a:vvveb:vvvebjs:*:*:*:*:*:*:*
- <= 1.7.4
A directory traversal vulnerability has been identified in VvvebJs version 1.7.2. This issue allows attackers to read arbitrary directories by exploiting the 'scan.php' file.
Exploitation of this vulnerability could lead to unauthorized access to sensitive files and directories on the server.
To reproduce this vulnerability, send a POST request to 'scan.php' with a 'mediaPath' parameter that includes directory traversal sequences. This will allow access to files outside the intended directory, such as system files.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.