CVE-2024-36531

nukeviet egovernment: Sicherheitsluecke

mediumEPSS 0.4%

Affected

  • nukeviet/egovernment between *..1.2.02
  • nukeviet/nukeviet between *..4.5.05

Description

nukeviet v.4.5 and before and nukeviet-egov v.1.2.02 and before are vulnerable to arbitrary code execution via the /admin/extensions/upload.php component.

Affected products

The following versions are affected. Older releases of the same product line are also vulnerable unless stated otherwise.

nukevietegovernment
1.2.02
nukevietnukeviet
4.5.05

Metrics

5.7
Source: nvd-v3
35.7 %
Elevated — this CVE ranks above at least 10% of all CVEs scored today.
Show all metrics
Severity
medium
no public PoC known
0.4 %
Low — model estimates < 1% exploitation likelihood.
Published
2024-06-10 00:00 UTC

References & sources