CVE-2025-11026: givanz Vvveb Configuration File information disclosure
A vulnerability was determined in givanz Vvveb up to 1.0.7.2. Affected by this vulnerability is an unknown functionality of the component Configuration File Handler. This manipulation causes information disclosure. The attack may be initiated remotely. The exploit has been publicly disclosed and may be utilized. Once again the project maintainer reacted very professional: "I accept the existence of these vulnerabilities. (...) I fixed the code to remove these vulnerabilities and will push the code to github and make a new release."
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-11026?
CVE-2025-11026 has a critical severity due to its potential for remote information disclosure.
How do I fix CVE-2025-11026?
To fix CVE-2025-11026, immediately update the givanz Vvveb to version 1.0.7.3 or later.
Who is affected by CVE-2025-11026?
CVE-2025-11026 affects all versions of givanz Vvveb up to 1.0.7.2.
What type of vulnerability is CVE-2025-11026?
CVE-2025-11026 is classified as an information disclosure vulnerability.
Can CVE-2025-11026 be exploited remotely?
Yes, CVE-2025-11026 can be exploited remotely by an attacker.