PT-2022-24880 · Melisplatform · Melisplatform/Melis-Front

Published

2022-10-11

·

Updated

2022-10-13

·

CVE-2022-39298

CVSS v3.1

7.7

High

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L
Name of the Vulnerable Software and Affected Versions melisplatform/melis-front versions prior to 5.0.1
Description The issue affects MelisFront, the engine that displays websites hosted on Melis Platform, handling tasks such as showing pages, plugins, URL rewriting, search optimization, and SEO. Attackers can deserialize arbitrary data on affected versions of melisplatform/melis-front, leading to the execution of arbitrary PHP code on the system without requiring authentication. This issue was addressed by restricting allowed classes when deserializing user-controlled data.
Recommendations For melisplatform/melis-front versions prior to 5.0.1, users should immediately upgrade to melisplatform/melis-front >= 5.0.1 to resolve the issue. As a temporary workaround, consider restricting the deserialization of user-controlled data to minimize the risk of exploitation.

Exploit

Fix

Deserialization of Untrusted Data

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2022-39298
GHSA-H479-2MV4-5C26

Affected Products

Melisplatform/Melis-Front