Executive brief
Vvveb, an open-source content management and e-commerce platform, contains a security flaw in its user registration process. An attacker can create an account with a specially crafted username containing malicious scripts. When a site administrator or another user views the attacker's profile or display name, these scripts can execute in their browser, potentially leading to unauthorized actions or data theft.
Technical details
A stored cross-site scripting (XSS) vulnerability exists in Vvveb versions prior to 1.0.8.3. The root cause is located in the Signup::addUser() controller, which fails to sanitize the 'username' POST parameter before assigning it to the 'display_name' field in the database. While the application may sanitize the primary username column, the 'display_name' column retains raw HTML and script markup. This allows unauthenticated remote attackers to inject malicious scripts during the signup process. These scripts are subsequently executed in the context of any user (including administrators) who views a page where the affected 'display_name' is rendered without proper output encoding. The issue is resolved in version 1.0.8.3.
Affected products
- givanz Vvveb < 1.0.8.3
Timeline
- 2026-05-13: patched: Version 1.0.8.3 released with sanitization fix.
- 2026-05-14: disclosed: Initial advisory published.