{"id":"CVE-2026-54065","aliases":[],"url":"https://o3.security/vulnerability/CVE-2026-54065","summary":"NukeViet: Path Traversal to Arbitrary File Deletion in Edit Comment Function","details":"## Summary\n\nPath Traversal to Arbitrary File Deletion in the Edit Comment admin function. An authenticated administrator can delete arbitrary files within the application root (e.g., `config.php`) by injecting a crafted `attach` parameter, rendering the application inoperable.\n\n## Affected Component\n\n`modules/comment/admin/edit.php`\n\n## Root Cause\n\nIn the vulnerable version, the `attach` parameter received via HTTP POST was not validated before being processed:\n\n```php\n// Vulnerable code (before fix)\n$attach = $nv_Request->get_string('attach', 'post', '', true);\nif (!empty($attach)) {\n    $attach = substr($attach, strlen(NV_BASE_SITEURL . NV_UPLOADS_DIR . '/' . $module_upload . '/'));\n}\n```\n\n`substr()` strips the first N characters (equal to the length of the upload URL prefix, e.g. 26 chars for `/nukeviet/uploads/comment/`). By padding the payload with exactly 26 arbitrary characters followed by a path traversal sequence, an attacker can store `../../<target>` directly into the database.\n\nWhen the comment is subsequently deleted, `del.php` reads `attach` from the database and calls:\n\n```php\nnv_deletefile(NV_UPLOADS_REAL_DIR . '/' . $module_upload . '/' . $row['attach']);\n```\n\n`nv_deletefile()` resolves the path via `realpath()` and only verifies the result is within `NV_ROOTDIR` — it does **not** restrict deletion to the uploads directory — allowing deletion of any file in the installation root.\n\n## Steps to Reproduce\n\n1. Log in as an administrator and navigate to **Admin → Comment Management**.\n2. Select any comment and open the Edit form.\n3. Intercept the POST request and set the `attach` parameter to:\n\n```\naaaaaaaaaaaaaaaaaaaaaaaaaa../../config.php\n```\n\n*(26 padding characters + traversal path)*\n\n4. Submit the request. The value `../../config.php` is now stored in the database.\n5. Delete the comment. `config.php` is deleted from the application root.\n6. The application immediately redirects to the install wizard, confirming the file has been removed.\n\n## Impact\n\n- Any file readable by the web server process within `NV_ROOTDIR` can be permanently deleted.\n- Deleting `config.php` causes a full application outage and exposes the install wizard.\n\n## Severity\n\n**CVSS v3.1 Base Score: 8.7 (High)**\n\n```\nCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:N/I:H/A:H\n```\n\n| Metric | Value |\n|--------|-------|\n| Attack Vector | Network |\n| Attack Complexity | Low |\n| Privileges Required | High (Admin required) |\n| User Interaction | None |\n| Scope | Changed |\n| Confidentiality | None |\n| Integrity | High |\n| Availability | High |\n\n## Fix\n\nAdded `nv_is_file()` validation before processing the `attach` value. This function uses `realpath()` and a regex check to ensure the file resolves to a path within the intended upload directory, rejecting any traversal attempts.\n\n```php\n// Fixed code\n$attach = $nv_Request->get_string('attach', 'post', '');\nif (!empty($attach) and nv_is_file($attach, NV_UPLOADS_DIR . '/' . $module_upload)) {\n    $attach = substr($attach, strlen(NV_BASE_SITEURL . NV_UPLOADS_DIR . '/' . $module_upload . '/'));\n} else {\n    $attach = '';\n}\n```","published":"2026-07-13T17:55:48Z","modified":"2026-07-13T18:11:45.808032Z","cvss":{"score":8.7,"severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:N/I:H/A:H"},"epss":null,"cisaKev":null,"exploitsKnown":null,"affectedPackages":[{"ecosystem":"Packagist","name":"nukeviet/nukeviet","fixedVersion":"4.6.00"}],"fix":null,"references":[{"type":"WEB","url":"https://github.com/nukeviet/nukeviet/security/advisories/GHSA-c9xg-64p9-f2jj"},{"type":"PACKAGE","url":"https://github.com/nukeviet/nukeviet"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-07-13T18:11:45.808032Z"}}