Vvveb before version 1.0.8.2 contains an information disclosure vulnerability that allows unauthenticated attackers to obtain sensitive server information by triggering unhandled exceptions in the password-reset module. Attackers can access the admin password-reset endpoint to trigger a fatal error caused by a missing namespace import, which exposes the absolute server file path, internal class namespaces, line numbers, and source code excerpts through the debug exception handler rendered to unauthenticated requests.
Metrics
Affected Vendors & Products
References
History
Wed, 06 May 2026 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 06 May 2026 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Vvveb before version 1.0.8.2 contains an information disclosure vulnerability that allows unauthenticated attackers to obtain sensitive server information by triggering unhandled exceptions in the password-reset module. Attackers can access the admin password-reset endpoint to trigger a fatal error caused by a missing namespace import, which exposes the absolute server file path, internal class namespaces, line numbers, and source code excerpts through the debug exception handler rendered to unauthenticated requests. | |
| Title | Vvveb < 1.0.8.2 Information Disclosure via Debug Exception Handler | |
| Weaknesses | CWE-1188 CWE-209 |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-05-06T19:42:17.377Z
Reserved: 2026-04-22T18:50:43.620Z
Link: CVE-2026-41931
Updated: 2026-05-06T19:40:06.364Z
Status : Deferred
Published: 2026-05-06T19:16:37.277
Modified: 2026-05-06T20:16:32.670
Link: CVE-2026-41931
No data.
OpenCVE Enrichment
Updated: 2026-05-06T21:30:12Z