clearsystem.php in NukeViet 4.4 allows CSRF with resultant HTML injection via the deltype parameter to the admin/index.php?nv=webtools&op=clearsystem URI.
{
"github_reviewed_at": "2024-04-24T19:54:59Z",
"github_reviewed": true,
"severity": "HIGH",
"nvd_published_at": "2020-06-23T20:15:00Z",
"cwe_ids": [
"CWE-352"
]
}