Description
Vvveb before version 1.0.8.2 contains a hard-coded credentials vulnerability in its docker-compose-apache.yaml configuration that allows unauthenticated attackers to access the bundled phpMyAdmin container with pre-configured database credentials. Attackers can connect to the phpMyAdmin port to gain unrestricted read and write access to the entire Vvveb database, including administrator password hashes, customer personally identifiable information, and order data, enabling account takeover and data manipulation.
INFO
Published Date :
2026-05-06T18:37:45.989Z
Last Modified :
2026-05-08T14:05:14.864Z
Source :
VulnCheck
AFFECTED PRODUCTS
The following products are affected by CVE-2026-41930 vulnerability.
| Vendors | Products |
|---|---|
| Givanz |
|
REFERENCES
Here, you will find a curated list of external links that provide in-depth information to CVE-2026-41930.