CVE-2025-9397: givanz Vvveb media.php unrestricted upload
A weakness has been identified in givanz Vvveb up to 1.0.7.2. Affected is an unknown function of the file /system/traits/media.php. Executing manipulation of the argument files[] can lead to unrestricted upload. The attack can be launched remotely. The exploit has been made available to the public and could be exploited. Applying a patch is advised to resolve this issue. The code maintainer explains, that "[he] fixed the code to remove this vulnerability and will make a new release".
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-9397?
CVE-2025-9397 is classified as a high severity vulnerability due to its potential for remote exploitation and unrestricted file uploads.
How do I fix CVE-2025-9397?
To fix CVE-2025-9397, upgrade the givanz Vvveb software to a version newer than 1.0.7.2 which addresses this vulnerability.
What are the consequences of exploiting CVE-2025-9397?
Exploiting CVE-2025-9397 can lead to unauthorized access to the server and potentially allow attackers to upload malicious files.
Which software versions are affected by CVE-2025-9397?
CVE-2025-9397 affects givanz Vvveb versions up to and including 1.0.7.2.
Can CVE-2025-9397 be exploited remotely?
Yes, CVE-2025-9397 can be exploited remotely, making it a critical vulnerability for affected systems.