Deserialization Vulnerability in NukeViet and NukeViet eGov Products
CVE-2024-36528

8.8HIGH

Key Information:

Vendor

NukeViet

Status
Vendor
CVE Published:
10 June 2024

What is CVE-2024-36528?

The NukeViet and NukeViet eGov platforms are impacted by a deserialization vulnerability present in versions 4.5 and earlier for NukeViet and 1.2.02 and earlier for NukeViet eGov. This vulnerability can be exploited to execute arbitrary code by manipulating requests sent to the admin extensions for downloading and uploading files. Attackers can exploit this flaw to compromise the web application, potentially leading to unauthorized access and control over the server.

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

.