CVE-2025-9728: givanz Vvveb login.tpl cross site scripting
A security vulnerability has been detected in givanz Vvveb 1.0.7.2. This affects an unknown part of the file app/template/user/login.tpl. Such manipulation of the argument Email/Password leads to cross site scripting. The attack can be executed remotely. The name of the patch is bbd4c42c66ab818142240348173a669d1d2537fe. Applying a patch is advised to resolve this issue.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2025-9728?
CVE-2025-9728 has been classified as a high-severity vulnerability due to its potential for cross-site scripting attacks.
How do I fix CVE-2025-9728?
To fix CVE-2025-9728, apply the patch provided by the vendor to secure the login template against manipulation.
What impacts does CVE-2025-9728 have on users?
CVE-2025-9728 can lead to unauthorized access or data manipulation through cross-site scripting, compromising user security.
Is CVE-2025-9728 exploitable remotely?
Yes, CVE-2025-9728 can be exploited remotely, making it accessible to attackers from outside the local network.
What software versions are affected by CVE-2025-9728?
CVE-2025-9728 specifically affects givanz Vvveb version 1.0.7.2.