EasyUse MailHunter Ultimate’s cookie deserialization function has an inadequate validation vulnerability. Deserializing a cookie containing malicious payload will trigger this insecure deserialization vulnerability, allowing an unauthenticated remote attacker to execute arbitrary code, manipulate system command or interrupt service.
Fixes

Solution

Contact tech support from EasyUse.


Workaround

No workaround given by the vendor.

History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: twcert

Published:

Updated: 2024-09-17T04:14:26.514Z

Reserved: 2022-07-05T00:00:00

Link: CVE-2022-35223

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2022-08-02T16:15:10.930

Modified: 2024-11-21T07:10:55.460

Link: CVE-2022-35223

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.