SB2026100237 - Cross-site scripting in NukeViet



SB2026100237 - Cross-site scripting in NukeViet

Published: October 2, 2026

Security Bulletin ID SB2026100237
CSH Severity
Low
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Remote access
Highest impact Data manipulation

Breakdown by Severity

Low 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 vulnerability.


1) Cross-site scripting (CVE-ID: N/A)

CWE-ID: CWE-79 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

CVSSv4: 4.8 [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N]


The vulnerability allows a remote user to execute arbitrary JavaScript in victims' browsers.

The vulnerability exists due to improper neutralization of input during web page generation in the global banners block when rendering sanitized banner content. A remote privileged user can store crafted HTML in banner content to execute arbitrary JavaScript in victims' browsers.

Exploitation requires a victim to view a page containing the banners block.


Remediation

Install update from vendor's website.