CVE-2025-11944: givanz Vvveb Raw SQL import.php import sql injection
A vulnerability was determined in givanz Vvveb up to 1.0.7.3. This affects the function Import of the file admin/controller/tools/import.php of the component Raw SQL Handler. This manipulation causes sql injection. The attack may be initiated remotely. The exploit has been publicly disclosed and may be utilized. Patch name: 52204b4a106b2fb02d16eee06a88a1f2697f9b35. It is recommended to apply a patch to fix this issue.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2025-11944?
CVE-2025-11944 is classified as a high severity vulnerability due to its potential for remote SQL injection attacks.
How can I fix CVE-2025-11944?
To fix CVE-2025-11944, update the givanz Vvveb software to version 1.0.7.4 or later to mitigate the SQL injection risk.
What components are affected by CVE-2025-11944?
CVE-2025-11944 affects the Raw SQL Handler component in the file admin/controller/tools/import.php of givanz Vvveb versions up to 1.0.7.3.
Can CVE-2025-11944 be exploited remotely?
Yes, CVE-2025-11944 can be exploited remotely, allowing attackers to manipulate SQL queries.
What type of vulnerability is CVE-2025-11944?
CVE-2025-11944 is categorized as an SQL injection vulnerability, which allows attackers to execute arbitrary SQL code.