CVE-2025-8772 | Vinades NukeViet up to 4.5.06 Module index.php?language=en&nv=upload server-side request forgery (EUVD-2025-24061)
A vulnerability labeled as problematic has been found in Vinades NukeViet up to 4.5.06. This affects an unknown function of the file /admin/index.php?language=en&nv=upload of the component Module Handler. Executing manipulation can lead to server-side request forgery.
The identification of this vulnerability is CVE-2025-8772. The attack may be launched remotely. Furthermore, there is an exploit available.
The vendor was contacted early about this disclosure but did not respond in any way.