modulesusersadminedit.php in NukeViet 4.4 allows CSRF to change a user’s password via an admin/index.php?nv=users&op=edit&userid= URI. The old password is not needed.
Source: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-13157
Reference (s):
- https://nukeviet.vn/en/
- https://www.exploit-db.com/exploits/48489

