Executive brief
Vvveb is a page builder CMS used to create websites, blogs, and ecommerce stores. A flaw in the global elements save function allows authenticated editors to write arbitrary PHP files to web-accessible directories, leading to persistent webshell placement and complete compromise of application confidentiality, integrity, and availability.
Technical details
The vulnerability exists in saveGlobalElements() within admin/controller/editor/global-trait.php, which concatenates user-controlled file paths from the data-v-save-global parameter directly to the theme directory without proper sanitization before passing to loadHTMLFile() and file_put_contents(). An authenticated user with the default Editor role and editor/* permission can submit crafted HTML to module=editor/editor&action=save to traverse outside the theme directory and overwrite existing writable PHP files. If web-accessible, the attacker can leverage the shipped public/vadmin/index.php entrypoint to execute editor-controlled PHP code. The fix in version 1.0.8.5 adds path sanitization and removes the editor/* permission for the Editor role.
Affected products
- Vvveb Vvveb 1.0.0 through 1.0.8.4
Timeline
- 2026-09-17: disclosed
- 2026-06-07: patched: Version 1.0.8.5 released with sanitization fix