CVE-2025-8522: givanz Vvvebjs node.js save.php path traversal
A vulnerability, which was classified as critical, was found in givanz Vvvebjs up to 2.0.4. Affected is an unknown function of the file /save.php of the component node.js. The manipulation of the argument File leads to path traversal. It is possible to launch the attack remotely. The complexity of an attack is rather high. The exploitability is told to be difficult. The exploit has been disclosed to the public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-8522?
CVE-2025-8522 is classified as a critical vulnerability.
How does CVE-2025-8522 affect systems?
CVE-2025-8522 allows for path traversal through the manipulation of the argument File in the /save.php file.
Which versions of Vvvebjs are affected by CVE-2025-8522?
CVE-2025-8522 affects givanz Vvvebjs versions up to and including 2.0.4.
Can CVE-2025-8522 be exploited remotely?
Yes, CVE-2025-8522 can be exploited remotely.
What is the recommended action to mitigate CVE-2025-8522?
To mitigate CVE-2025-8522, it is recommended to upgrade to a version of Vvvebjs that is not affected by this vulnerability.