9.8

CVE-2019-7725

includes/core/is_user.php in NukeViet before 4.3.04 deserializes the untrusted nvloginhash cookie (i.e., the code relies on PHP's serialization format when JSON can be used to eliminate the risk).
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
NukevietNukeviet Version < 4.3.04
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 2.54% 0.829
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 9.8 3.9 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvd@nist.gov 7.5 10 6.4
AV:N/AC:L/Au:N/C:P/I:P/A:P
CWE-502 Deserialization of Untrusted Data

The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.

https://github.com/nukeviet/nukeviet/blob/4.3.04/CHANGELOG.txt
Third Party Advisory
Release Notes
https://github.com/nukeviet/nukeviet/blob/nukeviet4.3/CHANGELOG.txt
Third Party Advisory
Release Notes
https://github.com/nukeviet/nukeviet/compare/4.3.03...4.3.04
Third Party Advisory
Release Notes
https://github.com/nukeviet/nukeviet/pull/2740/commits/05dfb9b4531f12944fe39556f58449b9a56241be
Patch
Third Party Advisory