PT-2025-41591 · E107 Cms · E107 Cms
Xancatos
·
Published
2025-10-10
·
Updated
2025-10-11
·
CVE-2025-61505
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
e107 CMS versions through 2.3.3
Description
The software contains a flaw due to insecure deserialization in the
install.php script. The script processes user-controlled input received in the previous steps POST parameter using unserialize(base64 decode()) without proper validation. Successful exploitation of this issue could result in remote code execution, arbitrary file operations, or denial of service, contingent on the presence of PHP object gadgets within the codebase.Recommendations
Update to a version beyond 2.3.3.
Fix
DoS
RCE
Deserialization of Untrusted Data
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
E107 Cms