PT-2025-9133 · Unknown · Pixelyoursite

Andres Roldan

·

Published

2025-02-28

·

Updated

2025-07-22

·

CVE-2025-0769

CVSS v4.0

6.3

Medium

VectorAV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions PixelYourSite - Your smart PIXEL (TAG) and API Manager version 10.1.1.1
Description The issue arises from unvalidated user input being used directly in an unserialize function. This occurs in the myapp/modules/facebook/facebook-server-a sync-task.php file.
Recommendations For version 10.1.1.1, consider validating all user input to prevent direct usage in the unserialize function as a temporary workaround. Restrict access to the myapp/modules/facebook/facebook-server-a sync-task.php file to minimize the risk of exploitation.

Fix

Deserialization of Untrusted Data

Weakness Enumeration

Related Identifiers

CVE-2025-0769

Affected Products

Pixelyoursite