Cross-site request forgery in NukeViet - #VU153178
Published: October 2, 2026
Vulnerability details
The vulnerability allows a remote attacker to perform destructive actions.
The vulnerability exists due to cross-site request forgery in the NukeViet CMS administration delete handlers when an authenticated administrator follows an attacker-supplied link. A remote attacker can persuade an authenticated administrator to follow a crafted link to perform destructive actions.