CVE-2020-13156
MEDIUMNukeViet 4.4 - Cross-Site Request Forgery via User Add Admin Endpoint
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2020-13156. PoCs published by JEBARAJ.
AI-analyzed exploit summary This exploit demonstrates a CSRF vulnerability in NukeViet CMS 4.4.00, allowing an attacker to change admin passwords, create new users, delete log files, and inject HTML via crafted forms. The PoC includes multiple HTML forms targeting specific endpoints without requiring prior authentication.
Description
modules\users\admin\add_user.php in NukeViet 4.4 allows CSRF to add a user account via the admin/index.php?nv=users&op=user_add URI.
Exploits (1)
This exploit demonstrates a CSRF vulnerability in NukeViet CMS 4.4.00, allowing an attacker to change admin passwords, create new users, delete log files, and inject HTML via crafted forms. The PoC includes multiple HTML forms targeting specific endpoints without requiring prior authentication.
References (2)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N