Executive brief
Vvveb CMS, a platform used for building websites and e-commerce stores, contains a security flaw in its order history page. A registered user can send specially crafted web requests to manipulate the website's database. This could allow an attacker to access sensitive information, modify data, or disrupt the website's operations.
Technical details
An authenticated SQL injection vulnerability exists in Vvveb CMS prior to version 1.0.8.3. The vulnerability is located in the frontend user order history page (/user/orders), where the 'order_by' and 'direction' request parameters are accepted from the URL and passed to the Orders component. These parameters are then directly concatenated into the SQL ORDER BY clause within the OrderSQL::getAll() method in storage/model/app/ordersql.mysqli.php without proper whitelisting or sanitization. A registered frontend user can exploit this to execute arbitrary SQL commands, potentially leading to full database compromise. The issue is resolved in version 1.0.8.3 by implementing stricter input validation.
Affected products
- givanz Vvveb CMS < 1.0.8.3
Timeline
- 2026-05-13: advisory: GitHub Security Advisory published
- 2026-05-15: disclosed: CVE published to NVD
- 2026-05-15: patched: Vulnerability fixed in version 1.0.8.3