vendor:
Nukedit
by:
3nitro - farhadkey
7.5
CVSS
HIGH
Unauthorized Admin Add Exploit
264
CWE
Product Name: Nukedit
Affected Version From: <= 4.9.6
Affected Version To: <= 4.9.6
Patch Exists: YES
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2020
Kapda HTML PoC For Nukedit <= 4.9.6
Nukedit is a Free Content Management. An Unauthorized Admin Add Exploit exists if the register.asp page is enabled. This exploit allows an attacker to add an admin user to the system by filling out the form and submitting it.
Mitigation:
Update to the latest version of Nukedit.