PT-2026-81238 · Typo3 · Html5 Video Player Vs. Powermail

·

CVE-2026-77138

·

Published

2026-08-25

·

Updated

2026-08-25

CVSS v4.0

9.3

Critical

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions HTML5 Video Player vs. Powermail (html5videoplayer powermail) (affected versions not specified)
Description The extension fails to safely process untrusted client input from an attacker-controlled cookie passed directly to the PHP unserialize() function. This allows a remote, unauthenticated attacker to provide a crafted serialized payload to trigger PHP Object Injection, which can lead to Remote Code Execution on the TYPO3 server. PHP Object Injection is a vulnerability that occurs when untrusted input is used to instantiate objects, potentially allowing the attacker to manipulate the application logic.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

RCE

Deserialization of Untrusted Data

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-77138

Affected Products

Html5 Video Player Vs. Powermail