Skip to main content
Vulnerability Database/CVE-2024-29272

CVE-2024-29272: VvvebJs Arbitrary File Upload RCE Flaw

CVE-2024-29272 is an arbitrary file upload vulnerability in VvvebJs that enables unauthenticated attackers to execute arbitrary code and access sensitive data. This article covers technical details, affected versions, and remediation.

Published:

CVE-2024-29272 Overview

CVE-2024-29272 is an arbitrary file upload vulnerability in VvvebJs, an open-source drag-and-drop website builder, affecting versions prior to 1.7.5. The flaw resides in the sanitizeFileName function within save.php and allows unauthenticated remote attackers to write arbitrary files to the server. Successful exploitation can lead to arbitrary code execution and disclosure of sensitive information. The weakness is classified under CWE-434: Unrestricted Upload of File with Dangerous Type.

Critical Impact

Unauthenticated remote attackers can upload arbitrary files, including PHP payloads, to a VvvebJs installation and execute code in the web server context.

Affected Products

  • Vvveb VvvebJs versions prior to 1.7.5
  • Deployments exposing save.php to untrusted networks
  • Web servers where PHP execution is enabled in the VvvebJs directory

Discovery Timeline

  • 2024-03-22 - CVE-2024-29272 published to the National Vulnerability Database (NVD)
  • 2026-06-17 - Last updated in NVD database

Technical Details for CVE-2024-29272

Vulnerability Analysis

VvvebJs exposes a save.php endpoint used by the web builder to persist HTML pages. The endpoint relies on a sanitizeFileName helper to normalize the destination filename. In versions before 1.7.5, that helper performed only lightweight regex-based sanitization and did not enforce a filename allowlist. As a result, an unauthenticated attacker reachable over the network could submit crafted requests that wrote files outside the intended path or with attacker-controlled names such as .htaccess.

The endpoint also lacked authentication and did not inspect saved HTML for embedded PHP tags before writing to disk. On a typical LAMP deployment, an attacker could combine these gaps to drop executable PHP content and turn a builder request into full remote code execution.

Root Cause

The root cause is insufficient input validation on a file write path. The pre-patch sanitizeFileName stripped disallowed characters and double-dots but did not reject sensitive basenames such as .htaccess or passwd, and did not gate execution on an authenticated session. The application also lacked an ALLOW_PHP control to block PHP tags in saved HTML.

Attack Vector

Exploitation requires only network access to the VvvebJs installation. The attacker sends a POST request to save.php supplying a controlled filename and content, causing the server to persist the file within the web root. No user interaction or prior authentication is required.

php
// Patched sanitizeFileName in save.php (excerpt)
define('MAX_FILE_LIMIT', 1024 * 1024 * 2);//2 Megabytes max html file size
define('ALLOW_PHP', false);//check if saved html contains php tag and don't save if not allowed
define('ALLOWED_OEMBED_DOMAINS', [
    'https://www.youtube.com/',
    'https://www.vimeo.com/',
    'https://www.twitter.com/'
]);//load urls only from allowed websites for oembed

function sanitizeFileName($file, $allowedExtension = 'html') {
    $basename = basename($file);
    $disallow = ['.htaccess', 'passwd'];
    if (in_array($basename, $disallow)) {
        showError('Filename not allowed!');
        return '';
    }

    //sanitize, remove double dot .. and remove get parameters if any
    $file = preg_replace('@\?.*$@', '', preg_replace('@\.{2,}@', '', preg_replace('@[^\/\\a-zA-Z0-9\-\._]@', '', $file)));

    if ($file) {
        $file = __DIR__ . DIRECTORY_SEPARATOR . $file;
    } else {
        return '';
    }

    //allow only .html extension
    if ($allowedExtension) {
        // extension enforcement continues...
    }
}

Source: VvvebJs commit c6422cf

Detection Methods for CVE-2024-29272

Indicators of Compromise

  • Unexpected files written to the VvvebJs directory, particularly .htaccess, .php, or files with double extensions
  • POST requests to save.php or scan.php originating from unauthenticated sources
  • New or modified HTML files under the VvvebJs web root containing <?php tags
  • Outbound connections from the web server process following writes to VvvebJs paths

Detection Strategies

  • Inspect web server access logs for POST requests to /save.php and /scan.php and correlate with file creation events in the VvvebJs directory
  • Compare on-disk VvvebJs files against a known-good baseline of the installed version
  • Alert on any process spawned by the web server user (for example php-fpm, apache) that executes shell utilities immediately after a POST to save.php

Monitoring Recommendations

  • Enable file integrity monitoring on the VvvebJs application directory and adjacent web-served paths
  • Forward web server access logs and PHP error logs to a centralized analytics platform for retrospective hunting
  • Track outbound network connections from the web server to detect post-exploitation command and control activity

How to Mitigate CVE-2024-29272

Immediate Actions Required

  • Upgrade VvvebJs to version 1.7.5 or later on all installations
  • Restrict network access to save.php and scan.php behind authentication or IP allowlisting until patching is complete
  • Audit the VvvebJs directory for unauthorized files, especially .htaccess and any files containing PHP tags
  • Rotate any credentials or API tokens that may have been exposed through arbitrary file reads

Patch Information

The fix was committed upstream in VvvebJs commit c6422cf and shipped in release 1.7.5. The patch introduces a filename denylist for .htaccess and passwd, adds an ALLOW_PHP constant to block persistence of HTML containing PHP tags, restricts oEmbed loading to an allowlist of domains, and applies a sanitizePath helper to the mediaPath parameter in scan.php. See the GitHub issue discussion for background.

Workarounds

  • Place save.php and scan.php behind HTTP basic authentication or a reverse proxy authentication layer
  • Configure the web server to deny PHP execution within any writable VvvebJs subdirectory
  • Deploy web application firewall rules that block requests to save.php with suspicious filename parameters such as .htaccess, .., or PHP extensions
bash
# Example Apache configuration to disable PHP execution in the VvvebJs writable directory
<Directory "/var/www/html/vvvebjs">
    <FilesMatch "\.(php|phtml|phar)$">
        Require all denied
    </FilesMatch>
</Directory>

# Restrict access to save.php and scan.php to a trusted IP range
<FilesMatch "^(save|scan)\.php$">
    Require ip 10.0.0.0/8
</FilesMatch>

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Default Legacy - Prefooter | Experience the World’s Most Advanced Cybersecurity Platform

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.