CVE-2019-7725

includes/core/is_user.php in NukeViet before 4.3.04 deserializes the untrusted nvloginhash cookie (i.e., the code relies on PHP's serialization format when JSON can be used to eliminate the risk).
Advertisement

NeevaHost hosting service

Configurations

Configuration 1 (hide)

cpe:2.3:a:nukeviet:nukeviet:*:*:*:*:*:*:*:*

Information

Published : 2020-12-30 21:15

Updated : 2021-01-05 06:44


NVD link : CVE-2019-7725

Mitre link : CVE-2019-7725


JSON object : View

CWE
CWE-502

Deserialization of Untrusted Data

Advertisement

dedicated server usa

Products Affected

nukeviet

  • nukeviet