CVE-2019-7725

Severity CVSS v4.0:
Pending analysis
Type:
CWE-502 Deserialization of Untrusted Dat
Publication date:
31/12/2020
Last modified:
05/01/2021

Description

includes/core/is_user.php in NukeViet before 4.3.04 deserializes the untrusted nvloginhash cookie (i.e., the code relies on PHP's serialization format when JSON can be used to eliminate the risk).

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:nukeviet:nukeviet:*:*:*:*:*:*:*:* 4.3.04 (excluding)