CVE-2024-29272 Overview
CVE-2024-29272 is an arbitrary file upload vulnerability in VvvebJs, an open-source drag-and-drop website builder, affecting versions prior to 1.7.5. The flaw resides in the sanitizeFileName function within save.php and allows unauthenticated remote attackers to write arbitrary files to the server. Successful exploitation can lead to arbitrary code execution and disclosure of sensitive information. The weakness is classified under CWE-434: Unrestricted Upload of File with Dangerous Type.
Critical Impact
Unauthenticated remote attackers can upload arbitrary files, including PHP payloads, to a VvvebJs installation and execute code in the web server context.
Affected Products
- Vvveb VvvebJs versions prior to 1.7.5
- Deployments exposing save.php to untrusted networks
- Web servers where PHP execution is enabled in the VvvebJs directory
Discovery Timeline
- 2024-03-22 - CVE-2024-29272 published to the National Vulnerability Database (NVD)
- 2026-06-17 - Last updated in NVD database
Technical Details for CVE-2024-29272
Vulnerability Analysis
VvvebJs exposes a save.php endpoint used by the web builder to persist HTML pages. The endpoint relies on a sanitizeFileName helper to normalize the destination filename. In versions before 1.7.5, that helper performed only lightweight regex-based sanitization and did not enforce a filename allowlist. As a result, an unauthenticated attacker reachable over the network could submit crafted requests that wrote files outside the intended path or with attacker-controlled names such as .htaccess.
The endpoint also lacked authentication and did not inspect saved HTML for embedded PHP tags before writing to disk. On a typical LAMP deployment, an attacker could combine these gaps to drop executable PHP content and turn a builder request into full remote code execution.
Root Cause
The root cause is insufficient input validation on a file write path. The pre-patch sanitizeFileName stripped disallowed characters and double-dots but did not reject sensitive basenames such as .htaccess or passwd, and did not gate execution on an authenticated session. The application also lacked an ALLOW_PHP control to block PHP tags in saved HTML.
Attack Vector
Exploitation requires only network access to the VvvebJs installation. The attacker sends a POST request to save.php supplying a controlled filename and content, causing the server to persist the file within the web root. No user interaction or prior authentication is required.
// Patched sanitizeFileName in save.php (excerpt)
define('MAX_FILE_LIMIT', 1024 * 1024 * 2);//2 Megabytes max html file size
define('ALLOW_PHP', false);//check if saved html contains php tag and don't save if not allowed
define('ALLOWED_OEMBED_DOMAINS', [
'https://www.youtube.com/',
'https://www.vimeo.com/',
'https://www.twitter.com/'
]);//load urls only from allowed websites for oembed
function sanitizeFileName($file, $allowedExtension = 'html') {
$basename = basename($file);
$disallow = ['.htaccess', 'passwd'];
if (in_array($basename, $disallow)) {
showError('Filename not allowed!');
return '';
}
//sanitize, remove double dot .. and remove get parameters if any
$file = preg_replace('@\?.*$@', '', preg_replace('@\.{2,}@', '', preg_replace('@[^\/\\a-zA-Z0-9\-\._]@', '', $file)));
if ($file) {
$file = __DIR__ . DIRECTORY_SEPARATOR . $file;
} else {
return '';
}
//allow only .html extension
if ($allowedExtension) {
// extension enforcement continues...
}
}
Source: VvvebJs commit c6422cf
Detection Methods for CVE-2024-29272
Indicators of Compromise
- Unexpected files written to the VvvebJs directory, particularly .htaccess, .php, or files with double extensions
- POST requests to save.php or scan.php originating from unauthenticated sources
- New or modified HTML files under the VvvebJs web root containing <?php tags
- Outbound connections from the web server process following writes to VvvebJs paths
Detection Strategies
- Inspect web server access logs for POST requests to /save.php and /scan.php and correlate with file creation events in the VvvebJs directory
- Compare on-disk VvvebJs files against a known-good baseline of the installed version
- Alert on any process spawned by the web server user (for example php-fpm, apache) that executes shell utilities immediately after a POST to save.php
Monitoring Recommendations
- Enable file integrity monitoring on the VvvebJs application directory and adjacent web-served paths
- Forward web server access logs and PHP error logs to a centralized analytics platform for retrospective hunting
- Track outbound network connections from the web server to detect post-exploitation command and control activity
How to Mitigate CVE-2024-29272
Immediate Actions Required
- Upgrade VvvebJs to version 1.7.5 or later on all installations
- Restrict network access to save.php and scan.php behind authentication or IP allowlisting until patching is complete
- Audit the VvvebJs directory for unauthorized files, especially .htaccess and any files containing PHP tags
- Rotate any credentials or API tokens that may have been exposed through arbitrary file reads
Patch Information
The fix was committed upstream in VvvebJs commit c6422cf and shipped in release 1.7.5. The patch introduces a filename denylist for .htaccess and passwd, adds an ALLOW_PHP constant to block persistence of HTML containing PHP tags, restricts oEmbed loading to an allowlist of domains, and applies a sanitizePath helper to the mediaPath parameter in scan.php. See the GitHub issue discussion for background.
Workarounds
- Place save.php and scan.php behind HTTP basic authentication or a reverse proxy authentication layer
- Configure the web server to deny PHP execution within any writable VvvebJs subdirectory
- Deploy web application firewall rules that block requests to save.php with suspicious filename parameters such as .htaccess, .., or PHP extensions
# Example Apache configuration to disable PHP execution in the VvvebJs writable directory
<Directory "/var/www/html/vvvebjs">
<FilesMatch "\.(php|phtml|phar)$">
Require all denied
</FilesMatch>
</Directory>
# Restrict access to save.php and scan.php to a trusted IP range
<FilesMatch "^(save|scan)\.php$">
Require ip 10.0.0.0/8
</FilesMatch>
Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.
