CVE-2020-4043

Severity CVSS v4.0:
Pending analysis
Type:
CWE-502 Deserialization of Untrusted Dat
Publication date:
10/06/2020
Last modified:
22/06/2020

Description

phpMussel from versions 1.0.0 and less than 1.6.0 has an unserialization vulnerability in PHP's phar wrapper. Uploading a specially crafted file to an affected version allows arbitrary code execution (discovered, tested, and confirmed by myself), so the risk factor should be regarded as very high. Newer phpMussel versions don't use PHP's phar wrapper, and are therefore unaffected. This has been fixed in version 1.6.0.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:phpmussel_project:phpmussel:*:*:*:*:*:*:*:* 1.0.0 (including) 1.6.0 (excluding)