Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2022-39297

Опубликовано: 12 окт. 2022
Источник: nvd
CVSS3: 7.7
CVSS3: 9.8
EPSS Низкий

Описание

MelisCms provides a full CMS for Melis Platform, including templating system, drag'n'drop of plugins, SEO and many administration tools. Attackers can deserialize arbitrary data on affected versions of melisplatform/melis-cms, and ultimately leads to the execution of arbitrary PHP code on the system. Conducting this attack does not require authentication. Users should immediately upgrade to melisplatform/melis-cms >= 5.0.1. This issue was addressed by restricting allowed classes when deserializing user-controlled data.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:melistechnology:meliscms:*:*:*:*:*:*:*:*
Версия до 5.0.1 (исключая)

EPSS

Процентиль: 75%
0.00888
Низкий

7.7 High

CVSS3

9.8 Critical

CVSS3

Дефекты

CWE-502
CWE-502

Связанные уязвимости

CVSS3: 7.7
github
больше 3 лет назад

melisplatform/melis-cms vulnerable to deserialization of untrusted data

EPSS

Процентиль: 75%
0.00888
Низкий

7.7 High

CVSS3

9.8 Critical

CVSS3

Дефекты

CWE-502
CWE-502