Givan Vvveb是Givan个人开发者的一款网站内容管理与组件构建系统。 Givan Vvveb 1.0.8.4之前版本存在授权问题漏洞,该漏洞源于admin/sql/sqlite/product_question.sql查询接受调用者控制的product_question_id且未验证product_question.product_id与product.admin_id,可能导致低权限供应商读取、修改或删除其他供应商产品的问答内容,操纵产品问答可见性和完整性。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
| CVE-2026-49221 | 8.8 HIGH | Vvveb digital asset authorization bypass allows Vendors to list, read, edit, or delete oth |
| CVE-2026-49228 | 8.8 HIGH | Vvveb product authorization bypass allows Vendors to read, duplicate, or delete other Vend |
| CVE-2026-49225 | 8.3 HIGH | Vvveb product revision authorization bypass allows Vendors to read, restore, or delete oth |
| CVE-2026-49226 | 8.3 HIGH | Vvveb post authorization bypass allows Authors to view, duplicate, or delete other Authors |
| CVE-2026-49224 | 8.3 HIGH | Vvveb post revision authorization bypass allows Authors to read, restore, or delete other |
| CVE-2026-49227 | 7.6 HIGH | Vvveb comment authorization bypass allows Authors to read, approve, edit, or delete commen |
| CVE-2026-49223 | 7.6 HIGH | Vvveb product review authorization bypass allows Vendors to read, approve, edit, or delete |
No comments yet