SB2026100233 - Multiple vulnerabilities in NukeViet



SB2026100233 - Multiple vulnerabilities in NukeViet

Published: October 2, 2026

Security Bulletin ID SB2026100233
CSH Severity
High
Patch available
YES
Number of vulnerabilities 7
Exploitation vector Remote access
Highest impact Data manipulation

Breakdown by Severity

High 14% Medium 43% Low 43%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 7 vulnerabilities.


1) Double Decoding of the Same Data (CVE-ID: CVE-2026-94599)

CWE-ID: CWE-174 - Double Decoding of the Same Data

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to execute arbitrary JavaScript in the origin of the NukeViet site.

The vulnerability exists due to double decoding of the same data in the news module search function when processing a crafted q parameter. A remote attacker can send a crafted link to a victim to execute arbitrary JavaScript in the origin of the NukeViet site.

User interaction is required to open the crafted link.


2) Cross-site scripting (CVE-ID: CVE-2026-94598)

CWE-ID: CWE-79 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N]


The vulnerability allows a remote attacker to execute arbitrary JavaScript in the context of a victim's page.

The vulnerability exists due to improper neutralization of input during web page generation in the NukeVietCoreRequest HTML sanitizer's filterTags() and filterAttr() functions when processing HTML content in an iframe srcdoc attribute. A remote attacker can submit crafted content containing forged internal marker sequences to execute arbitrary JavaScript in the context of a victim's page.

User interaction is required for a victim to view stored content containing the crafted iframe. Exploitation requires iframe to be included in the allowed HTML tags list.


3) Arbitrary file upload (CVE-ID: CVE-2026-94597)

CWE-ID: CWE-434 - Unrestricted Upload of File with Dangerous Type

CVSSv4: 7.7 [CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote user to execute arbitrary code.

The vulnerability exists due to unrestricted upload of files with dangerous types in the NukeViet file-upload pipeline when processing uploaded image files. A remote user can upload a valid image containing appended PHP code with a double-extension filename to execute arbitrary code.

Exploitation requires short_open_tag to be enabled and Apache mod_php to use an AddHandler directive for .php files.


4) Interpretation Conflict (CVE-ID: CVE-2026-94567)

CWE-ID: CWE-436 - Interpretation Conflict

CVSSv4: 8.5 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to execute arbitrary script in the site's origin.

The vulnerability exists due to an interpretation conflict in the SVG sanitizer in Files/Upload.php when processing uploaded SVG files. A remote attacker can upload a specially crafted SVG file containing a script hidden in an internal DTD entity to execute arbitrary script in the site's origin.

User interaction is required to open the uploaded SVG file in a browser.


5) Cross-site request forgery (CVE-ID: N/A)

CWE-ID: CWE-352 - Cross-Site Request Forgery (CSRF)

CVSSv4: 6.7 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to perform destructive actions.

The vulnerability exists due to cross-site request forgery in the NukeViet CMS administration delete handlers when an authenticated administrator follows an attacker-supplied link. A remote attacker can persuade an authenticated administrator to follow a crafted link to perform destructive actions.


6) Incomplete List of Disallowed Inputs (CVE-ID: N/A)

CWE-ID: CWE-184 - Incomplete List of Disallowed Inputs

CVSSv4: 2.1 [CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote user to cause the server to issue requests to internal hosts and disclose limited internal binary files.

The vulnerability exists due to incomplete validation of IPv4-mapped IPv6 addresses in the URL-based file import feature when submitting a hostname whose AAAA record resolves to a mapped internal address. A remote privileged user can submit a crafted hostname to cause the server to issue requests to internal hosts and disclose limited internal binary files.

Exploitation reaches internal IPv4 services only on operating systems that map IPv4-mapped IPv6 addresses to IPv4 endpoints; persisted responses must be recognized as allowed binary file types.


7) SQL injection (CVE-ID: N/A)

CWE-ID: CWE-89 - Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

CVSSv4: 2.1 [CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a remote user to disclose sensitive information.

The vulnerability exists due to SQL injection in the nv_admin_write_lang() function in admin/language/write.php when processing the dirlang GET parameter. A remote privileged user can submit a specially crafted dirlang parameter to disclose sensitive information.

The endpoint is available only on installations that are not sub-sites, and requests require a valid session-derived checksess token.


Remediation

Install update from vendor's website.