Vendor Review Manipulation in Vvveb CMS by Low-Privileged Users
CVE-2026-49223
What is CVE-2026-49223?
In Vvveb CMS versions prior to 1.0.8.4, a vulnerability exists in the backend review operations that allows a low-privileged vendor to manipulate reviews associated with another vendor's products. The system inadvertently accepts a user-controlled 'product_review_id' without proper validation against the associated 'product.admin_id' for the current admin user. This oversight permits attackers to view sensitive review content, ratings, and author information, as well as modify review statuses and delete reviews. Consequently, this not only compromises the visibility and integrity of product reviews but also poses significant risks to the credibility of the review process within the platform. This issue has been addressed in version 1.0.8.4.
Affected Version(s)
Vvveb < 1.0.8.4
