PT-2026-94367 · Git+1 · B2Evolution+1
CVSS v4.0
9.2
Critical
| Vector | AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
b2evolution CMS versions 6.7.8 through 7.2.5
Description
An incomplete fix in the
param check serialized array() function fails to reject payloads containing negative integer array keys. Unauthenticated attackers can send crafted serialized PHP objects via POST requests to the 'htsrv/call plugin.php' endpoint. This allows the bypass of validation to reach the unserialize() function, enabling the instantiation of arbitrary PHP objects with attacker-controlled properties. This may lead to remote code execution if suitable POP (Property Oriented Programming) gadget chains are present.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Deserialization of Untrusted Data
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
B2Evolution
B2Evolution Cms