includes/core/is_user.php in NukeViet before 4.3.04 deserializes the untrusted nvloginhash cookie (i.e., the code relies on PHP's serialization format when JSON can be used to eliminate the risk).
| Package (Ecosystem) | Introduced | Fixed | Limit |
|---|---|---|---|
| nukeviet/nukeviet(Packagist) | 0 | 4.3.04 | N/A |
CVSS Metrics