Phpok 6.1 has a deserialization vulnerability via framework/phpok_call.php.
The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.
Link | Tags |
---|---|
https://github.com/qinggan/phpok/issues/13 | issue tracking exploit third party advisory |
https://gist.github.com/T4rnRookie/e644c1dd8e025ab10fc3e3e4bfad2161 | third party advisory |