ZeroHour

CVE-2019-7725

CVSS 3.1
9.8 critical
EPSS
3%p84
Published
()
Modified
Description

includes/core/is_user.php in NukeViet before 4.3.04 deserializes the untrusted nvloginhash cookie (i.e., the code relies on PHP's serialization format when JSON can be used to eliminate the risk).

Vendors
nukeviet
Products
nukeviet
Weakness
CWE-502
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.