PT-2026-81238 · Typo3 · Html5 Video Player Vs. Powermail
CVSS v4.0
9.3
Critical
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X |
Name of the Vulnerable Software and Affected Versions
HTML5 Video Player vs. Powermail (html5videoplayer powermail) (affected versions not specified)
Description
The extension fails to safely process untrusted client input from an attacker-controlled cookie passed directly to the PHP
unserialize() function. This allows a remote, unauthenticated attacker to provide a crafted serialized payload to trigger PHP Object Injection, which can lead to Remote Code Execution on the TYPO3 server. PHP Object Injection is a vulnerability that occurs when untrusted input is used to instantiate objects, potentially allowing the attacker to manipulate the application logic.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
RCE
Deserialization of Untrusted Data
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Html5 Video Player Vs. Powermail