Record summary

CVE-2020-13155 has a selected CVSS score of 8.8 (high); EIP currently links 1 catalogued exploit.

Description

clearsystem.php in NukeViet 4.4 allows CSRF with resultant HTML injection via the deltype parameter to the admin/index.php?nv=webtools&op=clearsystem URI.

Description source: CVE List

Exploitation context

Available material

Catalogued exploits
1

Affected products and versions

1
ProductSourceVersion rangeStatus
GitHub Advisory4.4.0affected

Proofs of concept

1

Catalogued exploits

ExploitDBNukeViet VMS 4.4.00 - Cross-Site Request Forgery (Change Admin Password)ExploitDB exploitby JEBARAJNot analyzed1 file

linked to 3 vulnerabilities

ExploitDB

PoC details

References

4