PT-2025-41591 · E107 Cms · E107 Cms
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
e107 CMS versions through 2.3.3
Description
The software contains a flaw due to insecure deserialization in the
install.php script. The script processes user-controlled input received in the previous steps POST parameter using unserialize(base64 decode()) without proper validation. Successful exploitation of this issue could result in remote code execution, arbitrary file operations, or denial of service, contingent on the presence of PHP object gadgets within the codebase.Recommendations
Update to a version beyond 2.3.3.
Exploit
Fix
RCE
DoS
Deserialization of Untrusted Data
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
E107 Cms