8.8

CVE-2020-24036

Exploit
PHP object injection in the Ajax endpoint of the backend in ForkCMS below version 5.8.3 allows an authenticated remote user to execute malicious code.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Fork-cmsFork Cms Version < 5.8.3
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 2.94% 0.853
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 8.8 2.8 5.9
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvd@nist.gov 6.5 8 6.4
AV:N/AC:L/Au:S/C:P/I:P/A:P
CWE-502 Deserialization of Untrusted Data

The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.

http://forkcms.com
Product
http://seclists.org/fulldisclosure/2021/Mar/31
Third Party Advisory
Exploit
Mailing List
https://tech.feedyourhead.at/content/ForkCMS-PHP-Object-Injection-CVE-2020-24036
Patch
Third Party Advisory
Exploit
https://www.ait.ac.at/themen/cyber-security/pentesting/security-advisories/ait-sa-20210215-04
Patch
Third Party Advisory
Exploit