VvvebJs Unrestricted File Upload Vulnerability Allowing Remote Code Execution

Vulnerability

A vulnerability in VvvebJs version 1.7.2 allows for unrestricted file upload, enabling the upload of malicious files that could lead to remote code execution.

Impact

Exploitation of this vulnerability allows for unrestricted file uploads, which can be used to execute malicious code on the server.

Reproduction

To reproduce this vulnerability, upload a file through the application's file upload feature, such as 'upload.php'. The uploaded file can be a PHP file disguised with a different extension, like '.php16'. After uploading, the file can be accessed via the web server, potentially executing any embedded code.

Added: Dec 29, 2025, 9:19 PM
Updated: Dec 29, 2025, 9:19 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
10.0
exploitability
6.0
remediation
0.0
relevance
1.7
threat
6.4
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.