Information Disclosure Vulnerability in Givanz Vvveb by Givanz
CVE-2025-11028
Key Information:
Badges
What is CVE-2025-11028?
A security flaw has been identified in Givanz Vvveb up to version 1.0.7.2, specifically affecting the Image Handler component. This vulnerability allows attackers to manipulate images, leading to potential information disclosure. Remote exploitation is possible, and the exploit has already been made public, posing a risk to users. In response, the project maintainer has acknowledged the issue and is committed to rectifying it, with plans to update the code and release a new version on GitHub.
Affected Version(s)
Vvveb 1.0.7.0
Vvveb 1.0.7.1
Vvveb 1.0.7.2
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- 🟡
Public PoC available
- 👾
Exploit known to exist
Vulnerability published
Vulnerability Reserved