High severity8.8NVD Advisory· Published Jun 10, 2024· Updated Jun 17, 2026
CVE-2024-36528
CVE-2024-36528
Description
nukeviet v.4.5 and before and nukeviet-egov v.1.2.02 and before have a Deserialization vulnerability which results in code execution via /admin/extensions/download.php and /admin/extensions/upload.php.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
nukeviet/nukevietPackagist | <= 4.5 | — |
Affected products
4Patches
Vulnerability mechanics
References
3- mat4mee.notion.site/2-bug-chains-in-nukeViet-lead-to-RCE-bdd42b20b05a448fbe87c752b41bb15fnvdExploitThird Party AdvisoryWEB
- github.com/advisories/GHSA-mhj4-vrcv-x4xcghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2024-36528ghsaADVISORY
News mentions
0No linked articles in our index yet.