Описание
The ShopLentor WordPress plugin before 2.5.4 unserializes user input from cookies in order to track viewed products and user data, which could lead to PHP Object Injection.
Ссылки
- Patch
- ExploitThird Party Advisory
- Patch
- ExploitThird Party Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 2.5.4 (исключая)
cpe:2.3:a:hasthemes:shoplentor:*:*:*:*:*:wordpress:*:*
EPSS
Процентиль: 59%
0.00386
Низкий
9.8 Critical
CVSS3
Дефекты
Связанные уязвимости
CVSS3: 9.8
github
почти 3 года назад
The ShopLentor WordPress plugin before 2.5.4 unserializes user input from cookies in order to track viewed products and user data, which could lead to PHP Object Injection.
EPSS
Процентиль: 59%
0.00386
Низкий
9.8 Critical
CVSS3