Deserialization Vulnerability in NukeViet and NukeViet eGov Products
CVE-2024-36528
8.8HIGH
What is CVE-2024-36528?
The NukeViet and NukeViet eGov platforms are impacted by a deserialization vulnerability present in versions 4.5 and earlier for NukeViet and 1.2.02 and earlier for NukeViet eGov. This vulnerability can be exploited to execute arbitrary code by manipulating requests sent to the admin extensions for downloading and uploading files. Attackers can exploit this flaw to compromise the web application, potentially leading to unauthorized access and control over the server.
