Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2021-33898

Опубликовано: 06 июн. 2021
Источник: nvd
CVSS3: 8.1
CVSS2: 6.8
EPSS Низкий

Описание

In Invoice Ninja before 4.4.0, there is an unsafe call to unserialize() in app/Ninja/Repositories/AccountRepository.php that may allow an attacker to deserialize arbitrary PHP classes. In certain contexts, this can result in remote code execution. The attacker's input must be hosted at http://www.geoplugin.net (cleartext HTTP), and thus a successful attack requires spoofing that site or obtaining control of it.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:invoiceninja:invoice_ninja:*:*:*:*:*:*:*:*
Версия до 4.4.0 (исключая)

EPSS

Процентиль: 83%
0.01856
Низкий

8.1 High

CVSS3

6.8 Medium

CVSS2

Дефекты

CWE-502

Связанные уязвимости

github
больше 3 лет назад

In Invoice Ninja before 4.4.0, there is an unsafe call to unserialize() in app/Ninja/Repositories/AccountRepository.php that may allow an attacker to deserialize arbitrary PHP classes. In certain contexts, this can result in remote code execution. The attacker's input must be hosted at http://www.geoplugin.net (cleartext HTTP), and thus a successful attack requires spoofing that site or obtaining control of it.

CVSS3: 8.1
fstec
больше 4 лет назад

Уязвимость вызова unserialize() программного средства Invoice Ninja, позволяющая нарушителю выполнить произвольный код

EPSS

Процентиль: 83%
0.01856
Низкий

8.1 High

CVSS3

6.8 Medium

CVSS2

Дефекты

CWE-502