-
CVSS Score
-Basic Information
CVE ID
-
GHSA ID
-
EPSS Score
-
CWE
-
Published
-
Updated
-
KEV Status
-
Technology
-
The vulnerability stems from the absence of CSRF protection in the user creation functionality. The exploit demonstrates a working CSRF attack using a simple HTML form without requiring any anti-CSRF tokens. The file path modules/users/admin/add_user.php is explicitly referenced in both CVE and GHSA descriptions as the vulnerable component. While the exact function name isn't specified in public disclosures, the operation is triggered through the op=user_add parameter, indicating the handler for this operation in add_user.php is responsible for processing the insecure request.
| Package Name | Ecosystem | Vulnerable Versions | First Patched Version |
|---|---|---|---|
| nukeviet/nukeviet | composer | = 4.4 |