Vvveb before version 1.0.8.2 contains an unrestricted file upload vulnerability in the media upload handler that allows authenticated users with media-upload permissions to bypass extension restrictions by uploading a .htaccess file to map .phtml extensions to the PHP handler. Attackers can upload a .phtml file containing arbitrary PHP code and trigger execution by sending an unauthenticated HTTP GET request to the uploaded file, resulting in remote code execution with web server privileges.
Metrics
Affected Vendors & Products
References
History
Wed, 06 May 2026 22:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Givanz
Givanz vvveb |
|
| Vendors & Products |
Givanz
Givanz vvveb |
Wed, 06 May 2026 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 06 May 2026 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Vvveb before version 1.0.8.2 contains an unrestricted file upload vulnerability in the media upload handler that allows authenticated users with media-upload permissions to bypass extension restrictions by uploading a .htaccess file to map .phtml extensions to the PHP handler. Attackers can upload a .phtml file containing arbitrary PHP code and trigger execution by sending an unauthenticated HTTP GET request to the uploaded file, resulting in remote code execution with web server privileges. | |
| Title | Vvveb < 1.0.8.2 RCE via Media Upload Handler | |
| Weaknesses | CWE-434 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published: 2026-05-06T18:42:35.890Z
Updated: 2026-05-06T19:25:41.446Z
Reserved: 2026-04-22T18:50:43.621Z
Link: CVE-2026-41938
Updated: 2026-05-06T19:25:38.105Z
Status : Deferred
Published: 2026-05-06T19:16:37.680
Modified: 2026-05-06T20:16:32.993
Link: CVE-2026-41938
No data.
ReportizFlow