Lucene search

K
osvGoogleOSV:GHSA-4J79-4M6Q-77VF
HistoryMay 14, 2022 - 2:00 a.m.

Subrion CMS PHP Object Injection

2022-05-1402:00:54
Google
osv.dev
5
subrion cms
php
object injection
remote attackers
serialized data
salt cookie
login request

AI Score

7.3

Confidence

Low

EPSS

0.003

Percentile

70.3%

includes/classes/ia.core.users.php in Subrion CMS 4.0.5 allows remote attackers to conduct PHP Object Injection attacks via crafted serialized data in a salt cookie in a login request.

AI Score

7.3

Confidence

Low

EPSS

0.003

Percentile

70.3%

Related for OSV:GHSA-4J79-4M6Q-77VF