givanz Vvveb Information Disclosure Vulnerability in Configuration File Handler

Vulnerability

A vulnerability in givanz Vvveb versions through 1.0.7.2 allows remote attackers to access sensitive configuration files and system information. The issue arises from inadequate access controls in the default installation, enabling unauthorized retrieval of files such as composer.json, docker-compose.yaml, php.ini, and various nginx configuration files. Notably, the docker-compose.yaml file contains database credentials that could be reused for admin panel access or other services.

Impact

Exploitation of this vulnerability leads to unauthorized access to sensitive information, including configuration files and system data. The exposed database credentials in the docker-compose.yaml file could be used to access the database or admin panel, posing an additional risk.

Reproduction

The vulnerability can be reproduced by sending direct HTTP requests to the server hosting Vvveb CMS. The lack of proper access controls allows for the retrieval of sensitive files from various directories, including the public directory and specific admin-related paths.

Remediation

The project maintainer has acknowledged the vulnerability and stated that it has been fixed in the latest version. Users are advised to update to the patched version.

Added: Sep 26, 2025, 4:01 PM
Updated: Sep 26, 2025, 4:24 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
2.5
exploitability
8.7
remediation
0.0
relevance
0.6
threat
6.4
urgency
2.9
incentive
5.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.