Record summary

CVE-2020-13156 has a selected CVSS score of 6.5 (medium); EIP currently links 1 catalogued exploit.

Description

modules\users\admin\add_user.php in NukeViet 4.4 allows CSRF to add a user account via the admin/index.php?nv=users&op=user_add URI.

Description source: CVE List

Exploitation context

Available material

Catalogued exploits
1

Affected products and versions

1
ProductSourceVersion rangeStatus
GitHub Advisory4.4affected

Proofs of concept

1

Catalogued exploits

ExploitDBNukeViet VMS 4.4.00 - Cross-Site Request Forgery (Change Admin Password)ExploitDB exploitby JEBARAJNot analyzed1 file

linked to 3 vulnerabilities

ExploitDB

PoC details

References

4