5.1
/ 10
MEDIUM
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P
Description
A vulnerability was determined in givanz Vvveb up to 1.0.7.3. This affects the function Import of the file admin/controller/tools/import.php of the component Raw SQL Handler. This manipulation causes sql injection. The attack may be initiated remotely. The exploit has been publicly disclosed and may be utilized. Patch name: 52204b4a106b2fb02d16eee06a88a1f2697f9b35. It is recommended to apply a patch to fix this issue.
Basic Information
ID
CVE-2025-11944
Source
VulDB
Published
Oct 19, 2025 at 20:02
Affected Product
Vendor
givanz
Product
Vvveb
Version
1.0.7.0
Affected Versions
givanz Vvveb 1.0.7.0
givanz Vvveb 1.0.7.1
givanz Vvveb 1.0.7.2
givanz Vvveb 1.0.7.3
givanz Vvveb 1.0.7.1
givanz Vvveb 1.0.7.2
givanz Vvveb 1.0.7.3