Critical
CVSS 9.8
Overview
includes/core/is_user.php in NukeViet before 4.3.04 deserializes the untrusted nvloginhash cookie (i.e., the code relies on PHP's serialization format when JSON can be used to eliminate the risk).
includes/core/is_user.php in NukeViet before 4.3.04 deserializes the untrusted n...
includes/core/is_user.php in NukeViet before 4.3.04 deserializes the untrusted nvloginhash cookie (i.e., the code relies on PHP's serialization format when JSON can be used to eliminate the risk).
This vulnerability is rated 🔴 CRITICAL.
Recommended actions: