« Volver al listado

CVE-2026-41147

Estado: AplazadaAlta (8.7)—

NukeViet CMS is a multi Content Management System. Versions 4.5.07 and prior contain a Stored Cross-Site Scripting (XSS) vulnerability caused by insufficient server-side input sanitization in the Request class. The application relies primarily on client-side filtering to sanitize HTML tags and attributes in user-submitted content, which can be bypassed by intercepting and modifying HTTP requests directly (e.g., using Burp Suite). An attacker can inject malicious payloads which are stored server-side and executed in the browser of any user who views the content.

Leer descripción completaMostrar menos

Anyone viewing user-submitted content (such as administrators and moderators reviewing contact messages or comments) is impacted, and the vulnerability can be exploited by any anonymous visitor without authentication, with the Contact module used only as a proof of concept. Potential consequences include session hijacking through cookie theft, unauthorized actions performed under the victim's identity, defacement or redirection to phishing pages, and phishing attacks via manipulated email notifications. This issue has been fixed in version 4.5.08. If developers are unable to upgrade immediately, they should work around this issue by implementing server-side HTML sanitization in the Request class to strip or encode dangerous tags and attributes (e.g., <iframe>, srcdoc, event handlers like onerror/onload), enforcing a Content Security Policy (CSP) to restrict inline script execution, and set cookies with the HttpOnly flag to mitigate cookie theft via XSS.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

🎯 Técnicas ATT&CK

Cómo se explota esta vulnerabilidad y qué consigue el atacante, en el lenguaje de MITRE ATT&CK.

XSS almacenado en NukeViet CMS (CWE-79, vector AV:N/PR:L/UI:R) explotable sin autenticación. Los impactos incluyen ejecución de JavaScript en navegador, robo de sesiones/cookies, y defacement de contenido.

Inferido por nuestro agente de análisis a partir de la descripción oficial, el vector CVSS y la CWE, y comprobado por un supervisor. Puede contener errores.

🛡️ Mitigaciones ATT&CK que cubren estas técnicas

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-41147",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2026-41147",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "total"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2026-05-26T16:12:27.473907Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "security-advisories@github.com",
        "cvssData": {
          "scope": "CHANGED",
          "version": "3.1",
          "baseScore": 8.7,
          "attackVector": "NETWORK",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N",
          "integrityImpact": "HIGH",
          "userInteraction": "REQUIRED",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.8,
        "exploitabilityScore": 2.3
      }
    ]
  },
  "affected": [
    {
      "source": "security-advisories@github.com",
      "affectedData": [
        {
          "vendor": "nukeviet",
          "product": "nukeviet",
          "versions": [
            {
              "status": "affected",
              "version": "< 4.5.08"
            }
          ]
        }
      ]
    }
  ],
  "published": "2026-05-22T22:16:56.233",
  "references": [
    {
      "url": "https://github.com/nukeviet/nukeviet/commit/2a0860fbe22e2f6a3b90f802bf80b25e18699611",
      "source": "security-advisories@github.com"
    },
    {
      "url": "https://github.com/nukeviet/nukeviet/releases/tag/4.5.08",
      "source": "security-advisories@github.com"
    },
    {
      "url": "https://github.com/nukeviet/nukeviet/security/advisories/GHSA-64rr-pp78-62ww",
      "source": "security-advisories@github.com"
    }
  ],
  "vulnStatus": "Deferred",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "security-advisories@github.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-79"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "NukeViet CMS is a multi Content Management System. Versions 4.5.07 and prior contain a Stored Cross-Site Scripting (XSS) vulnerability caused by insufficient server-side input sanitization in the Request class. The application relies primarily on client-side filtering to sanitize HTML tags and attributes in user-submitted content, which can be bypassed by intercepting and modifying HTTP requests directly (e.g., using Burp Suite). An attacker can inject malicious payloads which are stored server-side and executed in the browser of any user who views the content. Anyone viewing user-submitted content (such as administrators and moderators reviewing contact messages or comments) is impacted, and the vulnerability can be exploited by any anonymous visitor without authentication, with the Contact module used only as a proof of concept. Potential consequences include session hijacking through cookie theft, unauthorized actions performed under the victim's identity, defacement or redirection to phishing pages, and phishing attacks via manipulated email notifications. This issue has been fixed in version 4.5.08. If developers are unable to upgrade immediately, they should work around this issue by implementing server-side HTML sanitization in the Request class to strip or encode dangerous tags and attributes (e.g., <iframe>, srcdoc, event handlers like onerror/onload), enforcing a Content Security Policy (CSP) to restrict inline script execution, and set cookies with the HttpOnly flag to mitigate cookie theft via XSS."
    },
    {
      "lang": "es",
      "value": "NukeViet CMS es un sistema de gestión de contenido múltiple. Las versiones 4.5.07 y anteriores contienen una vulnerabilidad de cross-site scripting (XSS) almacenado causada por una sanitización de entrada insuficiente del lado del server en la clase Request. La aplicación se basa principalmente en el filtrado del lado del cliente para sanitizar etiquetas y atributos HTML en el contenido enviado por el usuario, lo cual puede ser eludido interceptando y modificando directamente las solicitudes HTTP (por ejemplo, usando Burp Suite). Un atacante puede inyectar cargas útiles maliciosas que se almacenan del lado del server y se ejecutan en el navegador de cualquier usuario que vea el contenido. Cualquiera que vea contenido enviado por el usuario (como administradores y moderadores que revisan mensajes de contacto o comentarios) se ve afectado, y la vulnerabilidad puede ser explotada por cualquier visitante anónimo sin autenticación, con el módulo de Contacto utilizado solo como una prueba de concepto. Las posibles consecuencias incluyen el secuestro de sesión a través del robo de cookies, acciones no autorizadas realizadas bajo la identidad de la víctima, desfiguración o redirección a páginas de phishing, y ataques de phishing a través de notificaciones de correo electrónico manipuladas. Este problema ha sido solucionado en la versión 4.5.08. Si los desarrolladores no pueden actualizar de inmediato, deben solucionar este problema implementando la sanitización HTML del lado del server en la clase Request para eliminar o codificar etiquetas y atributos peligrosos (por ejemplo, <iframe>, srcdoc, manejadores de eventos como onerror/onload), aplicando una Política de Seguridad de Contenido (CSP) para restringir la ejecución de scripts en línea, y configurar las cookies con la bandera HttpOnly para mitigar el robo de cookies a través de XSS."
    }
  ],
  "lastModified": "2026-07-23T11:10:00.120",
  "sourceIdentifier": "security-advisories@github.com"
}