Cross-site scripting in NukeViet - #VU153173

 

Cross-site scripting in NukeViet - #VU153173

Published: October 2, 2026


Vulnerability identifier: #VU153173
CSH Severity: Low
CVSS v4: 4.8 [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N]
CVE-ID: N/A
CWE-ID: CWE-79
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to execute arbitrary JavaScript in victims' browsers.

The vulnerability exists due to improper neutralization of input during web page generation in the global banners block when rendering sanitized banner content. A remote privileged user can store crafted HTML in banner content to execute arbitrary JavaScript in victims' browsers.

Exploitation requires a victim to view a page containing the banners block.


Affected software

NukeViet

Remediation

Install security update from vendor's website.

NukeViet - addressed in versions 4.5.14, 4.6.03

External References

Related Security Bulletins