vendor:
Spitfire CMS
by:
LiquidWorm
7.5
CVSS
HIGH
PHP Object Injection
915
CWE
Product Name: Spitfire CMS
Affected Version From: 1.0.475
Affected Version To: 1.0.475
Patch Exists: NO
Related CWE:
CPE: a:claus_muus:spitfire_cms:1.0.475
Platforms Tested: nginx
2022
Spitfire CMS 1.0.475 – PHP Object Injection
The application is prone to a PHP Object Injection vulnerability due to the unsafe use of unserialize() function. A potential attacker, authenticated, could exploit this vulnerability by sending specially crafted requests to the web application containing malicious serialized input.
Mitigation:
Apply the vendor-provided patch or update to a version that has the patch applied.