Описание
includes/core/is_user.php in NukeViet before 4.3.04 deserializes the untrusted nvloginhash cookie (i.e., the code relies on PHP's serialization format when JSON can be used to eliminate the risk).
Ссылки
- Release NotesThird Party Advisory
- Release NotesThird Party Advisory
- Release NotesThird Party Advisory
- PatchThird Party Advisory
- Release NotesThird Party Advisory
- Release NotesThird Party Advisory
- Release NotesThird Party Advisory
- PatchThird Party Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 4.3.04 (исключая)
cpe:2.3:a:nukeviet:nukeviet:*:*:*:*:*:*:*:*
EPSS
Процентиль: 71%
0.00681
Низкий
9.8 Critical
CVSS3
7.5 High
CVSS2
Дефекты
CWE-502
Связанные уязвимости
EPSS
Процентиль: 71%
0.00681
Низкий
9.8 Critical
CVSS3
7.5 High
CVSS2
Дефекты
CWE-502