CVE-2025-2244
Severity CVSS v4.0:
CRITICAL
Type:
CWE-502
Deserialization of Untrusted Dat
Publication date:
04/04/2025
Last modified:
30/07/2025
Description
A vulnerability in the sendMailFromRemoteSource method in Emails.php as used in Bitdefender GravityZone Console unsafely uses php unserialize() on user-supplied input without validation. By crafting a malicious serialized payload, an attacker can trigger PHP object injection, perform a file write, and gain arbitrary command execution on the host system.
Impact
Base Score 4.0
9.50
Severity 4.0
CRITICAL
Base Score 3.x
9.80
Severity 3.x
CRITICAL
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:bitdefender:gravityzone:*:*:*:*:*:*:*:* | 6.41.2-1 (excluding) |
To consult the complete list of CPE names with products and versions, see this page



