CVE-2019-7725
Deserialization of Untrusted Data in NukeViet
9.8
CRITICAL
CVSS 3.1
EPSS 2.5%
Description
includes/core/is_user.php in NukeViet before 4.3.04 deserializes the untrusted nvloginhash cookie (i.e., the code relies on PHP's serialization format when JSON can be used to eliminate the risk).
How to fix CVE-2019-7725
To remediate CVE-2019-7725, upgrade the affected package to a fixed version below.
- Packagist/nukeviet/nukeviet—upgrade to 4.3.04 or later
Is CVE-2019-7725 being exploited?
Low — EPSS is 2.5%, meaning exploitation activity has not been observed at scale.
Affected packages (1)
- from 0, < 4.3.04
CVSS scores
| Source | Version | Severity | Vector |
|---|---|---|---|
| osv | CVSS 3.1 | CRITICAL9.8 | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |