b2evolution CMS 6.7.8 through 7.2.5 Object Injection via Negative Integer Array Key
28Vexday Risk Score
Sin señal de explotación. Ningún artefacto público de explotación conocido hasta ahora.
ssvc Trackcvss 9.2epss 0.8%
probabilidad de explotación
0.8%top 44% de las CVE
explotación observada
noninguna fuente lo reporta
b2evolution CMS versions 6.7.8 through 7.2.5 contain an incomplete fix for CVE-2016-8901 where the serialized-array object check in param_check_serialized_array() fails to reject payloads with negative integer array keys. Unauthenticated attackers can submit crafted serialized PHP objects via POST requests to htsrv/call_plugin.php that bypass validation and reach unserialize(), instantiating arbitrary PHP objects with attacker-chosen properties that may enable code execution if suitable POP gadget chains exist.
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Productos afectados
b2evolution · b2evolution CMSReferencias
https://b2evolution.net/news/2022/03/26/2022-update-eolhttps://gist.github.com/axg11/3e29501c33f6e1e05ac2a00107afd64ehttps://github.com/b2evolution/b2evolutionhttps://github.com/b2evolution/b2evolution/blob/7.2.5/htsrv/call_plugin.php#L49https://github.com/b2evolution/b2evolution/blob/7.2.5/inc/_core/_param.funcs.php#L2860https://github.com/b2evolution/b2evolution/commit/25c21cf9cc4261324001f9039509710b37ee2c4dhttps://github.com/b2evolution/b2evolution/commit/335abf09bcea61717bd00bc1e3889f8100ebd1bbhttps://github.com/b2evolution/b2evolution/commit/999b5ad1d59760d7e450ceb541f55432fc74cd27https://www.vulncheck.com/advisories/b2evolution-cms-6.7.8-through-7.2.5-object-injection-via-negative-integer-array-key