Welcome to our technology blog, where we provide you with the latest news, trends, and insights in the fast-paced world of tech. Join us on this exciting journey and discover the transformative power of technology today.
A CyStack Team Member - Simplifying Cybersecurity From A to Z
0 Views
0 Views
About the author
Sơn VõA CyStack Team Member - Simplifying Cybersecurity From A to Z
A CyStack Team Member - Simplifying Cybersecurity From A to Z
Stay up to dateGet the latest threat intelligence, cybersecurity reports from CyStack delivered to your inbox
Comments (0)
Sign in to join the discussion
Related posts
{"success":true,"head":"<title>HUST student uncovers critical vulnerability in NukeViet via WhiteHub - CyStack Blog</title>\n<meta name=\"robots\" content=\"noindex, nofollow\"/>\n<meta property=\"og:locale\" content=\"en_US\" />\n<meta property=\"og:type\" content=\"article\" />\n<meta property=\"og:title\" content=\"HUST student uncovers critical vulnerability in NukeViet via WhiteHub - CyStack Blog\" />\n<meta property=\"og:description\" content=\"A 4th-year student at Hanoi University of Science and Technology (HUST), active member of WhiteHub, has been honored by the […]\" />\n<meta property=\"og:url\" content=\"https://blog.cystack.org/blog/2026/05/19/hust-student-uncovers-critical-vulnerability-in-nukeviet-via-whitehub/\" />\n<meta property=\"og:site_name\" content=\"CyStack Blog\" />\n<meta property=\"article:tag\" content=\"en\" />\n<meta property=\"article:section\" content=\"News & Trends\" />\n<meta property=\"og:updated_time\" content=\"2026-06-23T19:58:49+07:00\" />\n<meta property=\"og:image\" content=\"https://s.cystack.net/resource/home/content/19173246/Slide.png\" />\n<meta property=\"og:image:secure_url\" content=\"https://s.cystack.net/resource/home/content/19173246/Slide.png\" />\n<meta property=\"og:image:width\" content=\"1920\" />\n<meta property=\"og:image:height\" content=\"1080\" />\n<meta property=\"og:image:alt\" content=\"Breaking News: Vietnamese student discovers & partners with NukeViet CMS to fix critical security vulnerability\" />\n<meta property=\"og:image:type\" content=\"image/png\" />\n<meta property=\"article:published_time\" content=\"2026-05-19T17:47:31+07:00\" />\n<meta property=\"article:modified_time\" content=\"2026-06-23T19:58:49+07:00\" />\n<meta name=\"twitter:card\" content=\"summary_large_image\" />\n<meta name=\"twitter:title\" content=\"HUST student uncovers critical vulnerability in NukeViet via WhiteHub - CyStack Blog\" />\n<meta name=\"twitter:description\" content=\"A 4th-year student at Hanoi University of Science and Technology (HUST), active member of WhiteHub, has been honored by the […]\" />\n<meta name=\"twitter:image\" content=\"https://s.cystack.net/resource/home/content/19173246/Slide.png\" />\n<meta name=\"twitter:label1\" content=\"Written by\" />\n<meta name=\"twitter:data1\" content=\"Sơn Võ\" />\n<meta name=\"twitter:label2\" content=\"Time to read\" />\n<meta name=\"twitter:data2\" content=\"5 minutes\" />\n<script type=\"application/ld+json\" class=\"rank-math-schema\">{\"@context\":\"https://schema.org\",\"@graph\":[{\"@type\":\"Organization\",\"@id\":\"https://blog.cystack.org/#organization\",\"name\":\"CyStack\",\"url\":\"https://blog.cystack.org\"},{\"@type\":\"WebSite\",\"@id\":\"https://blog.cystack.org/#website\",\"url\":\"https://blog.cystack.org\",\"name\":\"CyStack\",\"publisher\":{\"@id\":\"https://blog.cystack.org/#organization\"},\"inLanguage\":\"en-US\"},{\"@type\":\"ImageObject\",\"@id\":\"https://s.cystack.net/resource/home/content/19173246/Slide.png\",\"url\":\"https://s.cystack.net/resource/home/content/19173246/Slide.png\",\"width\":\"1920\",\"height\":\"1080\",\"caption\":\"Breaking News: Vietnamese student discovers & partners with NukeViet CMS to fix critical security vulnerability\",\"inLanguage\":\"en-US\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https://blog.cystack.org/blog/2026/05/19/hust-student-uncovers-critical-vulnerability-in-nukeviet-via-whitehub/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":\"1\",\"item\":{\"@id\":\"https://blog.cystack.org\",\"name\":\"Home\"}},{\"@type\":\"ListItem\",\"position\":\"2\",\"item\":{\"@id\":\"https://blog.cystack.org/blog/2026/05/19/hust-student-uncovers-critical-vulnerability-in-nukeviet-via-whitehub/\",\"name\":\"HUST student uncovers critical vulnerability in NukeViet via WhiteHub\"}}]},{\"@type\":\"WebPage\",\"@id\":\"https://blog.cystack.org/blog/2026/05/19/hust-student-uncovers-critical-vulnerability-in-nukeviet-via-whitehub/#webpage\",\"url\":\"https://blog.cystack.org/blog/2026/05/19/hust-student-uncovers-critical-vulnerability-in-nukeviet-via-whitehub/\",\"name\":\"HUST student uncovers critical vulnerability in NukeViet via WhiteHub - CyStack Blog\",\"datePublished\":\"2026-05-19T17:47:31+07:00\",\"dateModified\":\"2026-06-23T19:58:49+07:00\",\"isPartOf\":{\"@id\":\"https://blog.cystack.org/#website\"},\"primaryImageOfPage\":{\"@id\":\"https://s.cystack.net/resource/home/content/19173246/Slide.png\"},\"inLanguage\":\"en-US\",\"breadcrumb\":{\"@id\":\"https://blog.cystack.org/blog/2026/05/19/hust-student-uncovers-critical-vulnerability-in-nukeviet-via-whitehub/#breadcrumb\"}},{\"@type\":\"Person\",\"@id\":\"https://blog.cystack.org/author/sonvt/\",\"name\":\"S\\u01a1n V\\u00f5\",\"url\":\"https://blog.cystack.org/author/sonvt/\",\"image\":{\"@type\":\"ImageObject\",\"@id\":\"https://secure.gravatar.com/avatar/2ecc46dab0853cd3875309faad14bde0eb72099f5358ad072968dad8cbf55cd3?s=96&d=mm&r=g\",\"url\":\"https://secure.gravatar.com/avatar/2ecc46dab0853cd3875309faad14bde0eb72099f5358ad072968dad8cbf55cd3?s=96&d=mm&r=g\",\"caption\":\"S\\u01a1n V\\u00f5\",\"inLanguage\":\"en-US\"},\"worksFor\":{\"@id\":\"https://blog.cystack.org/#organization\"}},{\"@type\":\"BlogPosting\",\"headline\":\"HUST student uncovers critical vulnerability in NukeViet via WhiteHub - CyStack Blog\",\"keywords\":\"NukeViet,HUST\",\"datePublished\":\"2026-05-19T17:47:31+07:00\",\"dateModified\":\"2026-06-23T19:58:49+07:00\",\"author\":{\"@id\":\"https://blog.cystack.org/author/sonvt/\",\"name\":\"S\\u01a1n V\\u00f5\"},\"publisher\":{\"@id\":\"https://blog.cystack.org/#organization\"},\"description\":\"A 4th-year student at Hanoi University of Science and Technology (HUST), active member of WhiteHub, has been honored by the open-source NukeViet CMS platform after discovering and reporting a critical vulnerability through its Bug Bounty program. The development team subsequently confirmed and fully remediated the issue within just 1\\u20132 days.\",\"name\":\"HUST student uncovers critical vulnerability in NukeViet via WhiteHub - CyStack Blog\",\"@id\":\"https://blog.cystack.org/blog/2026/05/19/hust-student-uncovers-critical-vulnerability-in-nukeviet-via-whitehub/#richSnippet\",\"isPartOf\":{\"@id\":\"https://blog.cystack.org/blog/2026/05/19/hust-student-uncovers-critical-vulnerability-in-nukeviet-via-whitehub/#webpage\"},\"image\":{\"@id\":\"https://s.cystack.net/resource/home/content/19173246/Slide.png\"},\"inLanguage\":\"en-US\",\"mainEntityOfPage\":{\"@id\":\"https://blog.cystack.org/blog/2026/05/19/hust-student-uncovers-critical-vulnerability-in-nukeviet-via-whitehub/#webpage\"}}]}</script>\n"}
A 4th-year student at Hanoi University of Science and Technology (HUST), active member of WhiteHub, has been honored by the open-source NukeViet CMS platform after discovering and reporting a critical vulnerability through its Bug Bounty program. The development team subsequently confirmed and fully remediated the issue within just 1–2 days.
This article has been adapted from the original published by Vietnam Cybersecurity Magazine. Readers interested in the source reporting can find the original article at the link provided by the magazine.
From bug bounty hunting to two days of “dissecting” source code
Nguyen Quang Bang — a 4th-year Computer Science student at Hanoi University of Science and Technology — works part-time as a security tester at a tech company. The rest of his time, he spends on Bug Bounty programs on Intigriti and WhiteHub. While browsing the program catalog on WhiteHub, he stopped at NukeViet.
The CMS is no stranger to Vietnam’s tech industry: the country’s only open-source CMS to win the bronze prize at the Nhan Tai Dat Viet awards, with more than two decades of continuous development, recommended by the Ministry of Education and Training, and historically included in the procurement priority list for state agencies. A public codebase, a wide user community, monthly release cadence — for Bang, an ideal research target.
“I realized that by studying this platform’s source code, I’d get a real look at how developers actually build a system. That’s how the journey of dissecting the code began.”
Nguyen Quang Bang
HUST student
It wasn’t without obstacles. The first hurdle was building the test environment — deceptively simple, but ultimately more time-consuming than expected. Bang tried installing via Docker (a platform for packaging and deploying applications) and failed at the initial system setup. Switching to XAMPP (a software bundle that creates a local web server environment), things stabilized, although occasional domain issues remained. Past that stage, Bang began reading the code in earnest. More than two days later, the vulnerability surfaced.
Stored XSS and the risk of being controlled from within
The vulnerability Bang discovered is a Stored Cross-Site Scripting flaw, commonly abbreviated as Stored XSS. It belongs to one of the most dangerous attack classes against content management systems: the malicious payload doesn’t just flash by – it is written directly into the server’s database. Every time a user accesses the infected page, the code re-executes automatically, with no further attacker action required.
Illustration of a Stored XSS attack flow that hackers could exploit. Source: Vietnam Cybersecurity Magazine.
The real-world consequences can be severe. According to Bang, an attacker who successfully exploits this vulnerability could execute actions reserved for senior administrators, modify the system’s user interface, or tamper with the content of automated emails sent to admins. From there, phishing campaigns could be launched from within a platform users already trust, leaving no clear sign of intrusion.
For someone tackling a 20-year-old codebase for the first time, Bang admitted he had braced for something worse. The reality, however, was the opposite: “What impressed me most was how readable it was. I could easily locate the code containing the logic of a particular endpoint to analyze and test,” Bang recounted.
Bang gave high marks to NukeViet’s flexible role-based access control, noting that administrators can create various roles depending on operational needs. That said, according to Bang, systems with multiple privilege tiers and diverse input flows precisely require stricter and more synchronized security controls.
The “defense” model from the NukeViet community
NukeViet’s decision to run a Bug Bounty program on WhiteHub – rather than rely solely on its internal team – reflects a trend reshaping how Vietnamese vendors approach cybersecurity: open defense. Under this model, vendors publish scope, reward tiers, and rules, while the researcher community hunts within the authorized legal scope. A neutral platform owns the entire workflow of intake, triage, validation, and payout.
WhiteHub plays precisely that mediating role. Alongside the operational workflow, the platform preserves a secure communication channel between the two sides – a safety net that informal channels (personal email, social media) cannot guarantee, especially for reports carrying high legal exposure.
The NukeViet CMS team presents an award recognizing Nguyen Quang Bang’s discovery. Photo: Vietnam Cybersecurity Magazine.
From the process of studying NukeViet’s source code, Bang also gained a practical perspective on PHP — the platform’s core technology. According to Bang: “Many people hold prejudices about PHP, but in reality it still has a massive ecosystem. The fact that NukeViet continues to thrive on this stack shows the longevity of a product when it is operated correctly.”
Notable is the development team’s response process. Just 1-2 days after Bang’s report, NukeViet had confirmed and successfully fixed the issue. The development team even invited Bang to participate in a retest (independent verification) before officially releasing the patch in NukeViet 4.5.08 on GitHub. This receptiveness and processing speed demonstrate the professionalism of today’s NukeViet – WhiteHub ecosystem.
Advice for administrators currently running NukeViet
In recognition of this contribution, a NukeViet representative traveled directly to Hanoi University of Science and Technology to award and honor Nguyen Quang Bang. For a young “bug hunter” already balancing testing work at a tech company, this was significant professional encouragement.
Closing the conversation, Bang issued a clear recommendation to website administrators:
“Running outdated software versions creates opportunities for attackers to exploit known vulnerabilities. I recommend administrators continuously upgrade to the latest version to keep their systems safe.”
Nguyen Quang Bang
HUST student
The lesson from Nguyen Quang Bang and NukeViet is clear: when young talent is recognized and vendors know how to listen to the community, cybersecurity becomes a shared undertaking – firmly protecting the digital infrastructure of domestic organizations and businesses.
The Stored XSS vulnerability has now been fully remediated by the development team in NukeViet 4.5.08. To ensure system safety, administrators are advised to promptly check their installed version and upgrade to the latest release according to the vendor’s official guidance.
Article from Vietnam Cybersecurity Magizine
Translated by CyStack’s Marketing Team
HUST student uncovers critical vulnerability in NukeViet via WhiteHub - CyStack Blog