PT-2026-44164 · Drupal · Basket
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Drupal AlternativeCommerce (Basket) versions 0.0.0 through 2.1.17
Description
Drupal AlternativeCommerce (Basket) contains an issue where user-supplied data is not sufficiently sanitized before being passed to the PHP
unserialize() function. This allows for PHP Object Injection, a condition where an attacker can manipulate serialized objects to change the application's logic. If a viable gadget chain—a sequence of existing code fragments that can be executed during deserialization—is present in the site codebase or dependencies, this can lead to arbitrary PHP code execution.Recommendations
Update Drupal AlternativeCommerce (Basket) to version 2.1.17.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Basket