CVE-2026-41936

8.1

givanz · Vvveb

An XML external entity injection vulnerability in Vvveb allows authenticated site administrators to read arbitrary files and modify database records.

Executive summary

An XML external entity injection vulnerability in givanz Vvveb allows authenticated site administrators to read arbitrary files and escalate privileges, posing a high security risk to the application.

Vulnerability

This is an XML external entity injection vulnerability located in the admin Tools/Import feature of system/import/xml.php, requiring authenticated site_admin privileges to trigger.

Business impact

A successful exploit allows malicious actors with administrative privileges to read sensitive system files and overwrite administrator password hashes, resulting in complete unauthorized access and potential data compromise. Given the CVSS score of 8.1, this vulnerability poses a severe threat to operational integrity and confidentiality.

Remediation

Immediate Action: Update givanz Vvveb to version 1.0.8.2 or later to resolve the XML parser configuration flaw.

Proactive Monitoring: Monitor server access logs for anomalous requests targeting system/import/xml.php and review administrative account modifications.

Compensating Controls: Deploy a Web Application Filter rule to inspect incoming XML payloads for external entity declarations if immediate patching is not feasible.

Exploitation status

Public Exploit Available: Yes, a proof-of-concept reference exists via the security advisory and release notes.

Analyst recommendation

Organizations utilizing givanz Vvveb must treat this vulnerability with high priority due to its severe impact on system integrity and data confidentiality. Apply the primary remediation by updating to version 1.0.8.2 immediately to mitigate potential privilege escalation risks.

More givanz CVEs

Sources

Originally found and disclosed by Basant Kumar (@CyberWarrior9), VulnCheck, per the CVE Program record.