admin/blocks.php in Subrion CMS through 4.2.1 allows PHP Object Injection (with resultant file deletion) via serialized data in the subpages value within a block to blocks/edit.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2020-04-29T19:58:37

Updated: 2024-08-04T11:56:52.046Z

Reserved: 2020-04-29T00:00:00

Link: CVE-2020-12469

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2020-04-29T21:15:12.007

Modified: 2020-05-05T16:28:53.493

Link: CVE-2020-12469

cve-icon Redhat

No data.