CVE-2025-11029: givanz Vvveb cross-site request forgery
A weakness has been identified in givanz Vvveb up to 1.0.7.2. This vulnerability affects unknown code. Executing manipulation can lead to cross-site request forgery. The attack can be executed remotely. The exploit has been made available to the public and could be exploited. Once again the project maintainer reacted very professional: "I accept the existence of these vulnerabilities. (...) I fixed the code to remove these vulnerabilities and will push the code to github and make a new release."
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-11029?
CVE-2025-11029 is classified as a high-severity vulnerability due to its potential to enable cross-site request forgery attacks.
What is CVE-2025-11029?
CVE-2025-11029 is a vulnerability in givanz Vvveb versions up to 1.0.7.2 that allows for remote exploitation through cross-site request forgery.
How do I fix CVE-2025-11029?
To fix CVE-2025-11029, update the givanz Vvveb software to the latest version that addresses this vulnerability.
Who is affected by CVE-2025-11029?
CVE-2025-11029 affects users of givanz Vvveb version 1.0.7.2 and earlier.
Can CVE-2025-11029 be exploited remotely?
Yes, CVE-2025-11029 can be exploited remotely, making it crucial for affected users to apply patches immediately.