vendor:
Forma LMS
by:
Filippo Roncari
7.5
CVSS
HIGH
PHP Object Injection
CWE
Product Name: Forma LMS
Affected Version From: 1.3
Affected Version To: lower
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested:
Forma LMS 1.3 Multiple PHP Object Injection Vulnerabilities
Forma LMS 1.3 is prone to multiple PHP Object Injection vulnerabilities, due to a repeated unsafe use of the unserialize() function, which allows unprivileged users to inject arbitrary PHP objects. A potential attacker could exploit this vulnerability by sending specially crafted requests to the web application containing malicious serialized input, in order to execute code on the remote server or abuse arbitrary functionalities.