Deserialization of Untrusted Data vulnerability in LoftOcean CozyStay allows Object Injection.This issue affects CozyStay: from n/a before 1.7.1.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-17672 | Deserialization of Untrusted Data vulnerability in LoftOcean CozyStay allows Object Injection.This issue affects CozyStay: from n/a before 1.7.1. |
Fixes
Solution
Update the WordPress CozyStay theme to the latest available version (at least 1.7.1).
Workaround
No workaround given by the vendor.
References
History
Sat, 12 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Tue, 10 Jun 2025 13:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Deserialization of Untrusted Data vulnerability in LoftOcean CozyStay allows Object Injection.This issue affects CozyStay: from n/a before 1.7.1. | |
| Title | WordPress CozyStay < 1.7.1 - PHP Object Injection Vulnerability | |
| Weaknesses | CWE-502 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: Patchstack
Published:
Updated: 2025-06-10T13:37:36.407Z
Reserved: 2025-06-06T10:33:37.436Z
Link: CVE-2025-49507
No data.
Status : Awaiting Analysis
Published: 2025-06-10T13:15:23.283
Modified: 2025-06-12T16:06:39.330
Link: CVE-2025-49507
No data.
OpenCVE Enrichment
No data.
EUVD