VYPR
Medium severity5.7NVD Advisory· Published Jun 10, 2024· Updated Jun 17, 2026

CVE-2024-36531

CVE-2024-36531

Description

nukeviet v.4.5 and before and nukeviet-egov v.1.2.02 and before are vulnerable to arbitrary code execution via the /admin/extensions/upload.php component.

Affected products

5
  • cpe:2.3:a:nukeviet:egovernment:*:*:*:*:*:*:*:*
    Range: <=1.2.02
  • Vinades/Nukeviet3 versions
    cpe:2.3:a:nukeviet:nukeviet:*:*:*:*:*:*:*:*+ 2 more
    • cpe:2.3:a:nukeviet:nukeviet:*:*:*:*:*:*:*:*range: <=4.5.05
    • (no CPE)
    • (no CPE)range: <=4.5
  • Range: <=1.2.02

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.