PT-2022-24880 · Melisplatform · Melisplatform/Melis-Front
Published
2022-10-11
·
Updated
2022-10-13
·
CVE-2022-39298
CVSS v3.1
7.7
High
| Vector | AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L |
Name of the Vulnerable Software and Affected Versions
melisplatform/melis-front versions prior to 5.0.1
Description
The issue affects MelisFront, the engine that displays websites hosted on Melis Platform, handling tasks such as showing pages, plugins, URL rewriting, search optimization, and SEO. Attackers can deserialize arbitrary data on affected versions of melisplatform/melis-front, leading to the execution of arbitrary PHP code on the system without requiring authentication. This issue was addressed by restricting allowed classes when deserializing user-controlled data.
Recommendations
For melisplatform/melis-front versions prior to 5.0.1, users should immediately upgrade to melisplatform/melis-front >= 5.0.1 to resolve the issue. As a temporary workaround, consider restricting the deserialization of user-controlled data to minimize the risk of exploitation.
Exploit
Fix
Deserialization of Untrusted Data
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Melisplatform/Melis-Front