Vulnerabilities
Vulnerable Software
Nukeviet:  >> Nukeviet  >> 4.5  Security Vulnerabilities
A vulnerability, which was classified as problematic, has been found in Vinades NukeViet up to 4.5.06. This issue affects some unknown processing of the file /admin/index.php?language=en&nv=upload of the component Module Handler. The manipulation leads to server-side request forgery. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
CVSS Score
4.3
EPSS Score
0.0
Published
2025-08-09
nukeviet v.4.5 and before and nukeviet-egov v.1.2.02 and before have a Deserialization vulnerability which results in code execution via /admin/extensions/download.php and /admin/extensions/upload.php.
CVSS Score
8.8
EPSS Score
0.003
Published
2024-06-10
nukeviet v.4.5 and before and nukeviet-egov v.1.2.02 and before are vulnerable to arbitrary code execution via the /admin/extensions/upload.php component.
CVSS Score
5.7
EPSS Score
0.001
Published
2024-06-10
There is a Cross Site Scripting Stored (XSS) vulnerability in NukeViet CMS before 4.5.02.
CVSS Score
5.4
EPSS Score
0.002
Published
2022-06-21


Contact Us

Shodan ® - All rights reserved