Impact
A PHP object injection flaw allows an unauthenticated attacker to supply serialized objects that are unserialized without any class restrictions. An attacker can craft malicious serialized data for the billing_data POST field while setting the act parameter to login under from_billing_module. The flaw permits exploitation of arbitrary PHP object property chaining, resulting in remote code execution with root privileges on the host.
Affected Systems
The vulnerability affects Softaculous Virtualizor distributions prior to version 3.2.9 (including Patch 9) and the 3.0.0 series. Users running any of these releases are susceptible to the flaw.
Risk and Exploitability
The flaw carries a CVSS score of 9.2, indicating a high severity risk. EPSS data is not available, indicating no recent exploitation data. The vulnerability is not listed in the CISA KEV catalog. Attackers could exploit the flaw via the web interface without authentication, enumerated by the act and from_billing_module parameters, and achieve root-level code execution through available POP chains.
OpenCVE Enrichment