CVE Vulnerabilities

CVE-2024-25181

Server-Side Request Forgery (SSRF)

Published: Dec 29, 2025 | Modified: Jan 07, 2026
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

A critical vulnerability has been identified in givanz VvvebJs 1.7.2, which allows both Server-Side Request Forgery (SSRF) and arbitrary file reading. The vulnerability stems from improper handling of user-supplied URLs in the file_get_contents function within the save.php file.

Weakness

The web server receives a URL or similar request from an upstream component and retrieves the contents of this URL, but it does not sufficiently ensure that the request is being sent to the expected destination.

Affected Software

Name Vendor Start Version End Version
Vvvebjs Vvveb * 1.7.4 (including)

References