Описание
The Newsletter Manager plugin for WordPress is vulnerable to insecure deserialization in versions up to, and including, 1.5.1. This is due to unsanitized input from the 'customFieldsDetails' parameter being passed through a deserialization function. This potentially makes it possible for unauthenticated attackers to inject a serialized PHP object.
Ссылки
- Exploit
- Third Party Advisory
- Third Party Advisory
- Exploit
- Third Party Advisory
- Third Party Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 1.5.1 (включая)
cpe:2.3:a:xyzscripts:newsletter_manager:*:*:-:*:-:wordpress:*:*
EPSS
Процентиль: 73%
0.00765
Низкий
9.8 Critical
CVSS3
Дефекты
CWE-502
Связанные уязвимости
CVSS3: 9.8
github
больше 2 лет назад
The Newsletter Manager plugin for WordPress is vulnerable to insecure deserialization in versions up to, and including, 1.5.1. This is due to unsanitized input from the 'customFieldsDetails' parameter being passed through a deserialization function. This potentially makes it possible for unauthenticated attackers to inject a serialized PHP object.
EPSS
Процентиль: 73%
0.00765
Низкий
9.8 Critical
CVSS3
Дефекты
CWE-502