Critical severity9.8NVD Advisory· Published Dec 31, 2020· Updated Jun 17, 2026
CVE-2019-7726
CVE-2019-7726
Description
modules/banners/funcs/click.php in NukeViet before 4.3.04 has a SQL INSERT statement with raw header data from an HTTP request (e.g., Referer and User-Agent).
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
nukeviet/nukevietPackagist | < 4.3.04 | 4.3.04 |
Affected products
3- NukeViet/NukeVietdescription
Patches
Vulnerability mechanics
References
6- github.com/nukeviet/nukeviet/pull/2740/commits/05dfb9b4531f12944fe39556f58449b9a56241benvdPatchThird Party AdvisoryWEB
- github.com/advisories/GHSA-q4qv-fmwc-qxpxghsaADVISORY
- github.com/nukeviet/nukeviet/blob/4.3.04/CHANGELOG.txtnvdRelease NotesThird Party AdvisoryWEB
- github.com/nukeviet/nukeviet/blob/nukeviet4.3/CHANGELOG.txtnvdRelease NotesThird Party AdvisoryWEB
- github.com/nukeviet/nukeviet/compare/4.3.03...4.3.04nvdRelease NotesThird Party AdvisoryWEB
- nvd.nist.gov/vuln/detail/CVE-2019-7726ghsaADVISORY
News mentions
0No linked articles in our index yet.