SQL injection in NukeViet - #VU153180
Published: October 2, 2026
Vulnerability details
The vulnerability allows a remote user to disclose sensitive information.
The vulnerability exists due to SQL injection in the nv_admin_write_lang() function in admin/language/write.php when processing the dirlang GET parameter. A remote privileged user can submit a specially crafted dirlang parameter to disclose sensitive information.
The endpoint is available only on installations that are not sub-sites, and requests require a valid session-derived checksess token.