CVE-2018-1000059

ValidFormBuilder version 4.5.4 contains a PHP Object Injection vulnerability in Valid Form unserialize method that can result in Possible to execute unauthorised system commands remotely and disclose file contents in file system.
References
Link Resource
https://github.com/validformbuilder/validformbuilder/issues/126 Issue Tracking Third Party Advisory
https://github.com/validformbuilder/validformbuilder/issues/126 Issue Tracking Third Party Advisory
Configurations

Configuration 1 (hide)

cpe:2.3:a:validformbuilder:validform_builder:4.5.4:*:*:*:*:*:*:*

History

21 Nov 2024, 03:39

Type Values Removed Values Added
References () https://github.com/validformbuilder/validformbuilder/issues/126 - Issue Tracking, Third Party Advisory () https://github.com/validformbuilder/validformbuilder/issues/126 - Issue Tracking, Third Party Advisory

Information

Published : 2018-02-09 23:29

Updated : 2024-11-21 03:39


NVD link : CVE-2018-1000059

Mitre link : CVE-2018-1000059

CVE.ORG link : CVE-2018-1000059


JSON object : View

Products Affected

validformbuilder

  • validform_builder
CWE
CWE-502

Deserialization of Untrusted Data