Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-q5c4-rqq9-f524

Опубликовано: 14 дек. 2021
Источник: github
Github: Не прошло ревью

Описание

The ToTop Link WordPress plugin through 1.7.1 passes base64 encoded user input to the unserialize() PHP function, which could lead to PHP Object injection if a plugin installed on the blog has a suitable gadget chain.

The ToTop Link WordPress plugin through 1.7.1 passes base64 encoded user input to the unserialize() PHP function, which could lead to PHP Object injection if a plugin installed on the blog has a suitable gadget chain.

EPSS

Процентиль: 73%
0.00795
Низкий

Дефекты

CWE-502

Связанные уязвимости

CVSS3: 9.8
nvd
около 4 лет назад

The ToTop Link WordPress plugin through 1.7.1 passes base64 encoded user input to the unserialize() PHP function, which could lead to PHP Object injection if a plugin installed on the blog has a suitable gadget chain.

EPSS

Процентиль: 73%
0.00795
Низкий

Дефекты

CWE-502