Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Concrete CMS below 9.5.2 is vulnerable to PHP Object Injection via unserialize() calls in the Workflow, Form block, and File/Set components that lack the allowed_classes restriction.
Vulnerability Description
Concrete CMS below 9.5.2 is vulnerable to PHP Object Injection via unserialize() calls in the Workflow, Form block, and File/Set components that lack the allowed_classes restriction. An unauthenticated attacker may trigger arbitrary PHP object instantiation if a malicious serialized payload has been placed in the database. Thanks XananasX7 and Sanjorn Keeratirungsan (dizconnect) for both independently reporting. The Concrete CMS security team gave this vulnerability a CVSS v.4.0 score of 8.4 with vector CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N.
CVSS Information
N/A
Vulnerability Type
可信数据的反序列化
Vulnerability Title
concretecms 安全漏洞
Vulnerability Description
concretecms是Concrete CMS开源的一个内容管理系统。 concretecms 9.5.2之前版本存在安全漏洞,该漏洞源于Workflow、Form block和File/Set组件中unserialize调用缺少allowed_classes限制,可能导致PHP对象注入。
CVSS Information
N/A
Vulnerability Type
N/A