CVE-2020-13156: NukeViet Cross-Site Request Forgery (CSRF)
6.5
CVSS Score
3.1
Basic Information
CVE ID
GHSA ID
EPSS Score
0.31351%
CWE
Published
5/24/2022
Updated
4/24/2024
KEV Status
No
Technology
PHP
Technical Details
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
| Package Name | Ecosystem | Vulnerable Versions | First Patched Version |
|---|---|---|---|
| nukeviet/nukeviet | composer | = 4.4 |
Vulnerability Intelligence
Miggo AI
Root Cause Analysis
The vulnerability stems from the absence of CSRF protection in the user creation functionality. The exploit demonstrates a working CSRF attack using a simple HTML form without requiring any anti-CSRF tokens. The file path modules/users/admin/add_user.php is explicitly referenced in both CVE and GHSA descriptions as the vulnerable component. While the exact function name isn't specified in public disclosures, the operation is triggered through the op=user_add parameter, indicating the handler for this operation in add_user.php is responsible for processing the insecure request.