PT-2026-96921 · Softaculous · Virtualizor
CVSS v3.1
8.1
High
| Vector | AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Softaculous Virtualizor versions prior to 3.2.9 (Patch 9)
Softaculous Virtualizor version 3.0.0
Description
A PHP object injection issue exists in the billing module handler. Unauthenticated remote attackers can provide arbitrary serialized PHP objects for deserialization by setting the
act parameter to login while the from billing module parameter is present. By passing malicious serialized data through the billing data POST field, the unserialize() function processes the data without allowed classes restrictions. This allows the exploitation of POP chains (Property-Oriented Programming, a technique used to execute arbitrary code by leveraging existing classes in the application) to achieve remote code execution with root privileges.Recommendations
Update to version 3.2.9 (Patch 9) or later.
Update to a version newer than 3.0.0.
As a temporary mitigation, restrict access to the billing module handler to prevent unauthenticated remote requests.
Exploit
Fix
RCE
Deserialization of Untrusted Data
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Virtualizor