Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2020-14933

Опубликовано: 20 июн. 2020
Источник: redhat
CVSS3: 6.3

Описание

compose.php in SquirrelMail 1.4.22 calls unserialize for the $attachments value, which originates from an HTTP POST request. NOTE: the vendor disputes this because these two conditions for PHP object injection are not satisfied: existence of a PHP magic method (such as __wakeup or __destruct), and any attack-relevant classes must be declared before unserialize is called (or must be autoloaded).

An unsafe deserialization vulnerability was found in SquirrelMail. This flaw allows an authenticated user to craft malicious form data when submitting mail.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5squirrelmailOut of support scope

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-676
https://bugzilla.redhat.com/show_bug.cgi?id=1850184squirrelmail: use of unserialize function for the attachments value in compose.php

6.3 Medium

CVSS3

Связанные уязвимости

CVSS3: 8.8
ubuntu
больше 5 лет назад

compose.php in SquirrelMail 1.4.22 calls unserialize for the $attachments value, which originates from an HTTP POST request. NOTE: the vendor disputes this because these two conditions for PHP object injection are not satisfied: existence of a PHP magic method (such as __wakeup or __destruct), and any attack-relevant classes must be declared before unserialize is called (or must be autoloaded).

CVSS3: 8.8
nvd
больше 5 лет назад

compose.php in SquirrelMail 1.4.22 calls unserialize for the $attachments value, which originates from an HTTP POST request. NOTE: the vendor disputes this because these two conditions for PHP object injection are not satisfied: existence of a PHP magic method (such as __wakeup or __destruct), and any attack-relevant classes must be declared before unserialize is called (or must be autoloaded).

CVSS3: 8.8
debian
больше 5 лет назад

compose.php in SquirrelMail 1.4.22 calls unserialize for the $attachme ...

CVSS3: 8.8
github
больше 3 лет назад

compose.php in SquirrelMail 1.4.22 calls unserialize for the $attachments value, which originates from an HTTP POST request.

6.3 Medium

CVSS3