Vvveb before version 1.0.8.2 contains an XML external entity (XXE) injection vulnerability in the admin Tools/Import feature that allows authenticated site_admin users to read arbitrary files and modify database records. Attackers can exploit the XML parser configuration in system/import/xml.php to inject file:// or php://filter entity references that are resolved and persisted into the application database, enabling arbitrary file disclosure and administrator password hash overwriting for privilege escalation.
Metrics
Affected Vendors & Products
References
History
Wed, 06 May 2026 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 06 May 2026 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Vvveb before version 1.0.8.2 contains an XML external entity (XXE) injection vulnerability in the admin Tools/Import feature that allows authenticated site_admin users to read arbitrary files and modify database records. Attackers can exploit the XML parser configuration in system/import/xml.php to inject file:// or php://filter entity references that are resolved and persisted into the application database, enabling arbitrary file disclosure and administrator password hash overwriting for privilege escalation. | |
| Title | Vvveb < 1.0.8.2 XML External Entity Injection via Import | |
| Weaknesses | CWE-611 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-05-06T19:25:51.012Z
Reserved: 2026-04-22T18:50:43.620Z
Link: CVE-2026-41936
Updated: 2026-05-06T19:25:25.732Z
Status : Deferred
Published: 2026-05-06T19:16:37.550
Modified: 2026-05-06T20:16:32.880
Link: CVE-2026-41936
No data.
OpenCVE Enrichment
Updated: 2026-05-06T20:45:05Z