{"id":"GHSA-m8jx-mxf9-2rpw","summary":"NukeViet SQL Injection vulnerability","details":"SQL Injection vulnerability in NukeViet CMS module Shops 4.0.29 and 4.3 via the (1) listid parameter in detail.php and the (2) group_price or groupid parameters in search_result.php.\n\n### Fix Implementation:\nDownload the update package corresponding to the NukeViet version you are using, extract and upload to hosting according to NukeViet's structure:\nFor NukeViet 4.0 Official (4.0.29)\nFor NukeViet 4.1 Official (4.1.02)\nFor NukeViet 4.2 (4.2.01)\nAs for NukeViet 4.3, you can update according to the notice in the admin page or see here:  https://nukeviet.vn/vi/news/Tin-tuc/thong-bao-phat-hanh-nukeviet-4- 3-08-613.html","aliases":["CVE-2020-21809"],"modified":"2024-04-24T20:12:04.378669Z","published":"2022-05-24T19:09:25Z","database_specific":{"cwe_ids":["CWE-89"],"severity":"CRITICAL","github_reviewed":true,"github_reviewed_at":"2024-04-24T19:55:46Z","nvd_published_at":"2021-07-30T14:15:00Z"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2020-21809"},{"type":"WEB","url":"https://github.com/nukeviet/module-shops/commit/742c0e0f74364f7250c2a69f0a957d4e6317be68"},{"type":"PACKAGE","url":"https://github.com/nukeviet/nukeviet"},{"type":"WEB","url":"https://nukeviet.vn/vi/news/Tin-an-ninh/huong-dan-fix-loi-bao-mat-nukeviet-4-va-module-shops-612.html"},{"type":"WEB","url":"https://whitehub.net/submissions/1517"},{"type":"WEB","url":"https://whitehub.net/submissions/1518"}],"affected":[{"package":{"name":"nukeviet/nukeviet","ecosystem":"Packagist","purl":"pkg:composer/nukeviet/nukeviet"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"4.0"},{"fixed":"4.0.29"}]}],"versions":["4.0.24"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-m8jx-mxf9-2rpw/GHSA-m8jx-mxf9-2rpw.json"}},{"package":{"name":"nukeviet/nukeviet","ecosystem":"Packagist","purl":"pkg:composer/nukeviet/nukeviet"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"4.1"},{"fixed":"4.1.02"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-m8jx-mxf9-2rpw/GHSA-m8jx-mxf9-2rpw.json"}},{"package":{"name":"nukeviet/nukeviet","ecosystem":"Packagist","purl":"pkg:composer/nukeviet/nukeviet"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"4.2"},{"fixed":"4.2.01"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-m8jx-mxf9-2rpw/GHSA-m8jx-mxf9-2rpw.json"}},{"package":{"name":"nukeviet/nukeviet","ecosystem":"Packagist","purl":"pkg:composer/nukeviet/nukeviet"},"versions":["4.3"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-m8jx-mxf9-2rpw/GHSA-m8jx-mxf9-2rpw.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"}]}