Description
Vvveb before 1.0.8.3 contains an uncontrolled recursion vulnerability in the admin controller dispatch cycle where Base::init() repeatedly invokes permission() on error handlers, causing infinite recursion until PHP memory limits are exhausted. Attackers can send sustained requests to forbidden admin URLs from a low-privilege account to exhaust PHP memory on all workers and cause denial of service to legitimate traffic.
Problem types
Generation of Error Message Containing Sensitive Information
Product status
Any version before 1.0.8.3
c766e84b479dcf1bd1f25a44e4b9c9fa450769c8 (git)
Credits
Basant Kumar (@CyberWarrior9)
VulnCheck
References
github.com/givanz/Vvveb/releases/tag/1.0.8.3
github.com/...ommit/c766e84b479dcf1bd1f25a44e4b9c9fa450769c8
www.vulncheck.com/...ncontrolled-recursion-denial-of-service