ZeroHour

CVE-2022-47083

PoC
CVSS 3.1
8.8 high
EPSS
18%p97
Published
()
Modified
Description

A PHP Object Injection vulnerability in the unserialize() function Spitfire CMS v1.0.475 allows authenticated attackers to execute arbitrary code via sending crafted requests to the web application.

Vendors
spitfire project
Products
spitfire
Weakness
CWE-502
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.