Beveiligingsadvies

CVE-2026-41936

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2026-05-06 18:27:42
Laatst bijgewerkt 2026-07-28 01:48:54
Toegewezen door VulnCheck
CVSS-score 8.6
Status PUBLISHED

Beschrijving

Vvveb before version 1.0.8.2 contains an XML external entity (XXE) injection vulnerability in the admin Tools/Import feature that allows authenticated site_admin users to read arbitrary files and modify database records. Attackers can exploit the XML parser configuration in system/import/xml.php to inject file:// or php://filter entity references that are resolved and persisted into the application database, enabling arbitrary file disclosure and administrator password hash overwriting for privilege escalation.