vendor:
NukeViet CMS
by:
JEBARAJ
5.5
CVSS
MEDIUM
Cross-Site Request Forgery
352
CWE
Product Name: NukeViet CMS
Affected Version From: 4.4.00
Affected Version To: 4.4.00
Patch Exists: NO
Related CWE:
CPE: a:nukeviet:nukeviet:4.4.00
Platforms Tested: Windows 10 Pro
2020
NukeViet VMS 4.4.00 – Cross-Site Request Forgery (Change Admin Password)
NukeViet CMS v4.4.00 suffers from a Cross-Site Request Forgery (CSRF) vulnerability that allows an attacker to change the profile details and password of a user without knowing their old password. The vulnerability also allows the attacker to create a new user with admin privileges and delete sensitive and other log files.
Mitigation:
To mitigate this vulnerability, users are advised to apply the latest patch or update to a version of NukeViet CMS that is not affected by this vulnerability. Additionally, it is recommended to use strong and unique passwords for all user accounts.