includes/core/is_user.php in NukeViet before 4.3.04 deserializes the untrusted nvloginhash cookie (i.e., the code relies on PHPs serialization format when JSON can be used to eliminate the risk).
The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Nukeviet | Nukeviet | * | 4.3.04 (excluding) |