PT-2020-17850 · Php · Phpmussel
Maikuolan
·
Published
2020-06-10
·
Updated
2020-06-22
·
CVE-2020-4043
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
phpMussel versions 1.0.0 through 1.5.x
Description
The issue is an unserialization vulnerability in PHP's phar wrapper, allowing arbitrary code execution when a specially crafted file is uploaded to an affected version. The risk factor is very high. Newer phpMussel versions are unaffected as they do not use PHP's phar wrapper.
Recommendations
For versions 1.0.0 through 1.5.x, upgrade to at least version 1.6.0 to resolve the problem. However, upgrading to the latest available version is recommended to protect against potential future vulnerabilities.
As a temporary workaround, consider disabling archive checking by setting
check archives to false in the package's configuration to avoid execution of the affected parts of the codebase.Fix
Deserialization of Untrusted Data
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Phpmussel