CVE-2024-25182: Malicious File Upload
Published Dec 29, 2025
·Updated
givanz VvvebJs 1.7.2 suffers from a File Upload vulnerability via save.php.
Affected Software
2 affected components
givanz/VvvebJs
Vvveb Vvvebjs=1.7.2
Event History
Dec 29, 2025
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·09:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-25182?
CVE-2024-25182 is considered a critical vulnerability due to its potential for unauthorized file uploads.
2
How do I fix CVE-2024-25182?
To fix CVE-2024-25182, update to the latest version of VvvebJs which addresses the file upload vulnerability.
3
What types of attacks does CVE-2024-25182 expose systems to?
CVE-2024-25182 exposes systems to potential remote code execution and data theft due to unrestricted file uploads.
4
Is CVE-2024-25182 present in versions other than 1.7.2 of VvvebJs?
CVE-2024-25182 specifically affects version 1.7.2 of VvvebJs, making it vulnerable while other versions may not be impacted.
5
How can I assess if my system is vulnerable to CVE-2024-25182?
To assess vulnerability to CVE-2024-25182, check if your implementation of VvvebJs is running version 1.7.2 and test for the capability of file uploads.