Executive brief
Vvveb is a CMS and page builder used to create websites and online stores. An authenticated editor with admin-panel access can exploit a server-side request forgery (SSRF) vulnerability in the page editor to make the server fetch URLs pointing to internal services or cloud metadata endpoints, potentially exposing sensitive configuration, credentials, or service responses that should not be publicly accessible.
Technical details
The oEmbedProxy() handler in admin/controller/editor/editor.php accepts an attacker-controlled url parameter and passes it to getUrl() without proper validation. The validateUrl() function in system/functions.php checks only the hostname string and does not validate the resolved IP address. An authenticated admin-panel user with editor/* permission can invoke GET /admin/index.php?module=editor/editor&action=oEmbedProxy with a crafted hostname that resolves to private, loopback, link-local, or reserved addresses, causing the server to issue HTTP/HTTPS requests and return response bodies. No CSRF token is required because the action uses GET. The vulnerability was patched in version 1.0.8.5 by adding IP address resolution checks in validateUrl().
Affected products
- Vvveb Vvveb prior to 1.0.8.5
Timeline
- 2026-09-17: disclosed
- 2026-06-07: patched: Version 1.0.8.5 released with IP validation fix