MelisCms provides a full CMS for Melis Platform, including templating system, dragndrop of plugins, SEO and many administration tools. Attackers can deserialize arbitrary data on affected versions of melisplatform/melis-cms
, and ultimately leads to the execution of arbitrary PHP code on the system. Conducting this attack does not require authentication. Users should immediately upgrade to melisplatform/melis-cms
>= 5.0.1. This issue was addressed by restricting allowed classes when deserializing user-controlled data.
The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Meliscms | Melistechnology | * | 5.0.1 (excluding) |