Impact
The vulnerability in WHMCS occurs when the application deserializes data that has not been verified or sanitized. This unsafe deserialization allows an attacker to craft an object that, when unserialized, can execute arbitrary PHP code on the server. The flaw falls under CWE‑502 and could give a remote attacker full control of the web application environment.
Affected Systems
WebPros WHMCS, versions 9.0.0 through 9.0.7 and 8.0.0 through 8.13.6, are affected. The vulnerability is resolved in releases 9.0.8 and 8.13.7 and later. Only installations running the older releases remain vulnerable.
Risk and Exploitability
The CVSS score of 9.3 marks the flaw as critical, but the EPSS score is less than 1 %, indicating a low but nonzero likelihood of exploitation. The vulnerability is not listed in CISA’s KEV catalog. Based on the description, it is inferred that attackers can exploit the flaw remotely by submitting crafted input to a deserialization endpoint, which does not require local privileges. Successful exploitation would grant the attacker the ability to execute arbitrary code, compromise data, or take control of the hosting environment.
OpenCVE Enrichment