CVE-2024-25181
EUVD-2024-2251729.12.2025, 20:15
A critical vulnerability has been identified in givanz VvvebJs 1.7.2, which allows both Server-Side Request Forgery (SSRF) and arbitrary file reading. The vulnerability stems from improper handling of user-supplied URLs in the "file_get_contents" function within the "save.php" file.
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| vvveb | vvvebjs | 𝑥 ≤ 1.7.4 |
𝑥
= Vulnerable software versions