ZeroHour

CVE-2018-1000059

CVSS 3.0
9.8 critical
EPSS
2%p75
Published
()
Modified
Description

ValidFormBuilder version 4.5.4 contains a PHP Object Injection vulnerability in Valid Form unserialize method that can result in Possible to execute unauthorised system commands remotely and disclose file contents in file system.

Vendors
validformbuilder
Products
validform builder
Weakness
CWE-502
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.