VYPR

Egovernment

by Vinades

CVEs (2)

  • CVE-2024-36528HigJun 10, 2024
    risk 0.57cvss 8.8epss 0.01

    nukeviet v.4.5 and before and nukeviet-egov v.1.2.02 and before have a Deserialization vulnerability which results in code execution via /admin/extensions/download.php and /admin/extensions/upload.php.

  • CVE-2024-36531MedJun 10, 2024
    risk 0.37cvss 5.7epss 0.00

    nukeviet v.4.5 and before and nukeviet-egov v.1.2.02 and before are vulnerable to arbitrary code execution via the /admin/extensions/upload.php component.