PT-2018-9422 · Nethesis · Openpsa

Prodigysml

·

Publicado

2018-06-26

·

Atualizado

2020-08-24

·

CVE-2018-1000525

CVSS v3.1

9.8

Crítica

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions openpsa versions prior to the version containing commit 097eae0
Description The issue concerns a PHP Object Injection vulnerability. It occurs when form data passed as GET request variables is specially crafted to contain serialized PHP objects, potentially leading to information disclosure and remote code execution. The vulnerability can be exploited through specially crafted GET request variables.
Recommendations For versions prior to the version containing commit 097eae0, update to a version that includes the fix for this issue. As a temporary workaround, consider restricting access to sensitive data and validating all GET request variables to prevent the injection of malicious serialized PHP objects. Avoid using user-supplied input in the deserialization process until the issue is resolved.

Exploit

Correção

Deserialization of Untrusted Data

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2018-1000525

Produtos afetados

Openpsa