← Back to CVE List

CVE-2019-7725

Published: 2020-12-31T05:15Z
Last Modified: 2024-11-21T04:48Z
Source: MITRE CVE List
License: MITRE-CVE-TOS
includes/core/is_user.php in NukeViet before 4.3.04 deserializes the untrusted nvloginhash cookie (i.e., the code relies on PHP's serialization format when JSON can be used to eliminate the risk). > MITRE Terms of Use apply – see LICENSE‑MITRE.txt