Executive brief
Vvveb, an open-source content management system, contains a flaw that allows users with low-level access to grant themselves administrative control. By manipulating their profile settings, an attacker can elevate their account to a 'Super Administrator' role. This level of access allows them to take full control of the website, including the ability to upload malicious code and access sensitive data.
Technical details
A privilege escalation vulnerability exists in Vvveb versions prior to 1.0.8.1 due to improper input validation in the admin user profile save endpoint. The application fails to restrict the modification of sensitive object attributes (CWE-915), allowing an authenticated user to inject a 'role_id=1' parameter into their profile update request. By doing so, a low-privileged user can escalate their privileges to Super Administrator. Once escalated, the attacker can leverage administrative features, such as plugin uploads, to achieve remote code execution (RCE) on the server. The issue is addressed in version 1.0.8.1.
Affected products
- givanz Vvveb < 1.0.8.1
Timeline
- 2026-04-19: patched: Version 1.0.8.1 released
- 2026-04-20: disclosed: Initial vulnerability disclosure
- 2026-04-20: advisory: NVD publication date