An issue was discovered in phpFox before 4.8.14. The url request parameter passed to the /core/redirect route is not properly sanitized before being used in a call to the unserialize() PHP function. This can be exploited by remote, unauthenticated attackers to inject arbitrary PHP objects into the application scope, allowing them to perform a variety of attacks, such as executing arbitrary PHP code.
Advisories
Source ID Title
EUVD EUVD EUVD-2023-50983 An issue was discovered in phpFox before 4.8.14. The url request parameter passed to the /core/redirect route is not properly sanitized before being used in a call to the unserialize() PHP function. This can be exploited by remote, unauthenticated attackers to inject arbitrary PHP objects into the application scope, allowing them to perform a variety of attacks, such as executing arbitrary PHP code.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2024-09-06T13:48:48.784Z

Reserved: 2023-10-27T00:00:00

Link: CVE-2023-46817

cve-icon Vulnrichment

Updated: 2024-08-02T20:53:21.761Z

cve-icon NVD

Status : Modified

Published: 2023-11-03T05:15:30.867

Modified: 2024-11-21T08:29:22.147

Link: CVE-2023-46817

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses