CVE-2018-1000059

ValidFormBuilder version 4.5.4 contains a PHP Object Injection vulnerability in Valid Form unserialize method that can result in Possible to execute unauthorised system commands remotely and disclose file contents in file system.
References
Link Resource
https://github.com/validformbuilder/validformbuilder/issues/126 Issue Tracking Third Party Advisory
Advertisement

NeevaHost hosting service

Configurations

Configuration 1 (hide)

cpe:2.3:a:validformbuilder:validform_builder:4.5.4:*:*:*:*:*:*:*

Information

Published : 2018-02-09 15:29

Updated : 2020-08-24 10:37


NVD link : CVE-2018-1000059

Mitre link : CVE-2018-1000059


JSON object : View

CWE
CWE-502

Deserialization of Untrusted Data

Advertisement

dedicated server usa

Products Affected

validformbuilder

  • validform_builder