PT-2026-48390 · Unknown · Concrete Cms
CVSS v4.0
8.4
High
| Vector | AV:L/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X |
Name of the Vulnerable Software and Affected Versions
Concrete CMS versions prior to 9.5.2
Description
PHP Object Injection occurs due to insecure deserialization within the Permission, Cache, and Search components. These components use the
unserialize() function on stored data without restricting allowed classes. An unauthenticated attacker can trigger arbitrary PHP object instantiation if a malicious serialized payload is placed in the database, which may lead to remote code execution. This process requires the attacker to have high privileges to write the malicious serialized data to the relevant store.Recommendations
Upgrade to version 9.5.2 or later.
Exploit
Fix
RCE
Deserialization of Untrusted Data
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Concrete Cms