b2evolution CMS 6.7.8 through 7.2.5 Object Injection via Negative Integer Array Key
28Vexday Risk Score
Sem sinal de exploração. Nenhum artefato público de exploração conhecido até agora.
ssvc Trackcvss 9.2epss 0.8%
probabilidade de exploração
0.8%top 44% das CVEs
exploração observada
nãonenhuma fonte reporta
b2evolution CMS versions 6.7.8 through 7.2.5 contain an incomplete fix for CVE-2016-8901 where the serialized-array object check in param_check_serialized_array() fails to reject payloads with negative integer array keys. Unauthenticated attackers can submit crafted serialized PHP objects via POST requests to htsrv/call_plugin.php that bypass validation and reach unserialize(), instantiating arbitrary PHP objects with attacker-chosen properties that may enable code execution if suitable POP gadget chains exist.
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Produtos afetados
b2evolution · b2evolution CMSReferências
https://b2evolution.net/news/2022/03/26/2022-update-eolhttps://gist.github.com/axg11/3e29501c33f6e1e05ac2a00107afd64ehttps://github.com/b2evolution/b2evolutionhttps://github.com/b2evolution/b2evolution/blob/7.2.5/htsrv/call_plugin.php#L49https://github.com/b2evolution/b2evolution/blob/7.2.5/inc/_core/_param.funcs.php#L2860https://github.com/b2evolution/b2evolution/commit/25c21cf9cc4261324001f9039509710b37ee2c4dhttps://github.com/b2evolution/b2evolution/commit/335abf09bcea61717bd00bc1e3889f8100ebd1bbhttps://github.com/b2evolution/b2evolution/commit/999b5ad1d59760d7e450ceb541f55432fc74cd27https://www.vulncheck.com/advisories/b2evolution-cms-6.7.8-through-7.2.5-object-injection-via-negative-integer-array-key