PT-2020-13360 · Nukeviet · Nukeviet

Published

2020-06-23

·

Updated

2022-05-24

·

CVE-2020-13155

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions NukeViet version 4.4
Description The issue allows for CSRF with resultant HTML injection via the deltype parameter to the "admin/index.php?nv=webtools&op=clearsystem" URI. This can be exploited through the clearsystem.php file.
Recommendations For NukeViet version 4.4, consider disabling the clearsystem.php file or restricting access to the "admin/index.php?nv=webtools&op=clearsystem" URI until a patch is available. Avoid using the deltype parameter in the affected URI to minimize the risk of exploitation.

Exploit

Fix

CSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-13155
GHSA-7RW5-6PR4-FGH3

Affected Products

Nukeviet