Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
modules\users\admin\edit.php in NukeViet 4.4 allows CSRF to change a user's password via an admin/index.php?nv=users&op=edit&userid= URI. The old password is not needed.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
VINADES NukeViet 跨站请求伪造漏洞
Vulnerability Description
VINADES NukeViet是越南VINADES公司的一套开源的内容管理系统(CMS)。 VINADES NukeViet 4.4版本中的modulesusersadminedit.php文件存在跨站请求伪造漏洞。攻击者可借助特制URL利用该漏洞更改用户密码(不需要旧密码)。
CVSS Information
N/A
Vulnerability Type
N/A