PT-2019-12711 · Virim · Virim

Published

2019-05-20

·

Updated

2019-08-23

·

CVE-2019-12240

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Virim plugin version 0.4
Description The issue allows for Insecure Deserialization via s values, t values, or c values in the graph.php file.
Recommendations For Virim plugin version 0.4, consider disabling the deserialization functionality in graph.php until a patch is available to prevent exploitation. Restrict access to the graph.php file to minimize the risk of exploitation. Avoid using the s values, t values, or c values in the affected file until the issue is resolved.

Exploit

Fix

Deserialization of Untrusted Data

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2019-12240

Affected Products

Virim