PHP object injection in the Ajax endpoint of the backend in ForkCMS below version 5.8.3 allows an authenticated remote user to execute malicious code.
The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.
Link | Tags |
---|---|
http://forkcms.com | product |
https://www.ait.ac.at/themen/cyber-security/pentesting/security-advisories/ait-sa-20210215-04 | exploit third party advisory patch |
https://tech.feedyourhead.at/content/ForkCMS-PHP-Object-Injection-CVE-2020-24036 | exploit third party advisory patch |
http://seclists.org/fulldisclosure/2021/Mar/31 | mailing list exploit third party advisory |