Описание
includes/classes/ia.core.users.php in Subrion CMS 4.0.5 allows remote attackers to conduct PHP Object Injection attacks via crafted serialized data in a salt cookie in a login request.
Ссылки
- Third Party AdvisoryVDB Entry
- Issue TrackingPatchThird Party Advisory
- Third Party AdvisoryVDB Entry
- Issue TrackingPatchThird Party Advisory
Уязвимые конфигурации
Конфигурация 1
cpe:2.3:a:intelliants:subrion:4.0.5:*:*:*:*:*:*:*
EPSS
Процентиль: 82%
0.01765
Низкий
9.8 Critical
CVSS3
7.5 High
CVSS2
Дефекты
CWE-94
Связанные уязвимости
EPSS
Процентиль: 82%
0.01765
Низкий
9.8 Critical
CVSS3
7.5 High
CVSS2
Дефекты
CWE-94