PT-2020-16982 · Collne+1 · Usc-E-Shop+1

Ramuel Gall

·

Published

2020-11-07

·

Updated

2021-07-21

·

CVE-2020-28339

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions usc-e-shop (aka Collne Welcart e-Commerce) plugin versions prior to 1.9.36 for WordPress
Description The issue allows Object Injection due to usces unserialize. There is no complete POP chain.
Recommendations For versions prior to 1.9.36, update to version 1.9.36 or later to resolve the issue. As a temporary workaround, consider restricting the use of the usces unserialize function until a patch is applied.

Exploit

Fix

Deserialization of Untrusted Data

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-28339

Affected Products

Wordpress
Usc-E-Shop