← volver
CVE-2017-7411

CVE-2017-7411

50Vexday Risk Score

Corrige pronto. Ella tiene exploit funcional público.

ssvc Attendepss 67%
de la publicación al arma50 días
Publicada en NVD30 oct
1ª PoC+50d
metasploit23 oct
probabilidad de explotación
67%top 1% de las CVE
explotación observada
noninguna fuente lo reporta
3 exploit(s) público(s)
An issue was discovered in Enalean Tuleap 9.6 and prior versions. The vulnerability exists because the User::getRecentElements() method is using the unserialize() function with a preference value that can be arbitrarily manipulated by malicious users through the REST API interface, and this can be exploited to inject arbitrary PHP objects into the application scope, allowing an attacker to perform a variety of attacks (including but not limited to Remote Code Execution).
Productos afectados
n/a · n/a
⚠ Recursos públicos, para evaluar la exposición de sistemas que controlas o estás autorizado a probar. Prueba solo con autorización.