CVE-2020-13155
HIGHNukeViet 4.4 - Cross-Site Request Forgery via clearsystem.php deltype Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2020-13155. PoCs published by JEBARAJ.
AI-analyzed exploit summary This exploit demonstrates a CSRF vulnerability in NukeViet CMS 4.4.00, allowing an attacker to change admin passwords, create new users, delete log files, and inject HTML via crafted forms. The PoC includes multiple HTML forms targeting specific endpoints without requiring prior authentication.
Description
clearsystem.php in NukeViet 4.4 allows CSRF with resultant HTML injection via the deltype parameter to the admin/index.php?nv=webtools&op=clearsystem URI.
Exploits (1)
This exploit demonstrates a CSRF vulnerability in NukeViet CMS 4.4.00, allowing an attacker to change admin passwords, create new users, delete log files, and inject HTML via crafted forms. The PoC includes multiple HTML forms targeting specific endpoints without requiring prior authentication.
References (2)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H