Impact
The vulnerability exists in WHMCS through deserialization of untrusted data, allowing a remote attacker to spawn arbitrary code on the affected installation. The weakness is classified as unsafe deserialization (CWE-502), a failure to verify or isolate input that may be crafted by an attacker. The impact is broad; any user who can trigger the deserialization path can achieve full control of the web server, leading to data theft, site takeover, or distribution of malware.
Affected Systems
WHMCS versions 9.0.0 through 9.0.7 and 8.0.0 through 8.13.6 are impacted. The fix is available in version 9.0.8 and 8.13.7 and later releases. Only installations using those older versions are susceptible.
Risk and Exploitability
The CVSS score of 9.3 marks the flaw as critical. No EPSS score is available, and the vulnerability is not listed in the CISA KEV catalog. Based on the description, the attack vector is remote and requires only the ability to supply input that triggers deserialization, making it likely exploitable over the web without local user privileges.
OpenCVE Enrichment