PT-2020-17850 · Php · Phpmussel

Maikuolan

·

Published

2020-06-10

·

Updated

2020-06-22

·

CVE-2020-4043

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions phpMussel versions 1.0.0 through 1.5.x
Description The issue is an unserialization vulnerability in PHP's phar wrapper, allowing arbitrary code execution when a specially crafted file is uploaded to an affected version. The risk factor is very high. Newer phpMussel versions are unaffected as they do not use PHP's phar wrapper.
Recommendations For versions 1.0.0 through 1.5.x, upgrade to at least version 1.6.0 to resolve the problem. However, upgrading to the latest available version is recommended to protect against potential future vulnerabilities. As a temporary workaround, consider disabling archive checking by setting check archives to false in the package's configuration to avoid execution of the affected parts of the codebase.

Fix

Deserialization of Untrusted Data

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-4043
GHSA-QR95-4MQ5-R3FH

Affected Products

Phpmussel