PT-2025-9133 · Unknown · Pixelyoursite
Andres Roldan
·
Published
2025-02-28
·
Updated
2025-07-22
·
CVE-2025-0769
CVSS v4.0
6.3
Medium
| Vector | AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
PixelYourSite - Your smart PIXEL (TAG) and API Manager version 10.1.1.1
Description
The issue arises from unvalidated user input being used directly in an
unserialize function. This occurs in the myapp/modules/facebook/facebook-server-a sync-task.php file.Recommendations
For version 10.1.1.1, consider validating all user input to prevent direct usage in the
unserialize function as a temporary workaround. Restrict access to the myapp/modules/facebook/facebook-server-a sync-task.php file to minimize the risk of exploitation.Fix
Deserialization of Untrusted Data
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Pixelyoursite