Spitfire CMS 1.0.475 PHP Object Injection

Discussion in 'News Aggregator' started by Packet Storm, 10 Dec 2022.

  1. Packet Storm

    Packet Storm Guest

    Spitfire CMS version 1.0.475 is prone to a PHP object injection vulnerability due to the unsafe use of unserialize() function. A potential attacker, authenticated, could exploit this vulnerability by sending specially crafted requests to the web application containing malicious serialized input.

    Continue reading...
     

Share This Page

Loading...