Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-3v3g-3pf9-fgcf

Опубликовано: 18 сент. 2026
Источник: github
Github: Не прошло ревью
CVSS4: 7.7
CVSS3: 7.5

Описание

Cotonti 1.0.0 passes the base64-decoded cb parameter to unserialize() without allowed_classes restriction in the comments plugin EditAction. Registered users with comment write permissions can instantiate arbitrary PHP objects and potentially achieve file write or code execution through gadget chains.

Cotonti 1.0.0 passes the base64-decoded cb parameter to unserialize() without allowed_classes restriction in the comments plugin EditAction. Registered users with comment write permissions can instantiate arbitrary PHP objects and potentially achieve file write or code execution through gadget chains.

EPSS

Процентиль: 38%
0.00439
Низкий

7.7 High

CVSS4

7.5 High

CVSS3

Дефекты

CWE-502

Связанные уязвимости

CVSS3: 7.5
nvd
2 дня назад

Cotonti 1.0.0 passes the base64-decoded cb parameter to unserialize() without allowed_classes restriction in the comments plugin EditAction. Registered users with comment write permissions can instantiate arbitrary PHP objects and potentially achieve file write or code execution through gadget chains.

EPSS

Процентиль: 38%
0.00439
Низкий

7.7 High

CVSS4

7.5 High

CVSS3

Дефекты

CWE-502