Impact
The vulnerability is an object injection flaw that permits an unauthenticated attacker to embed serialized PHP objects containing negative integer array keys into a POST request sent to htsrv/call_plugin.php. These payloads bypass the param_check_serialized_array() safeguard, reach the unserialize() routine, and instantiate arbitrary PHP objects. Because the attacker can set object properties at will, the flaw can lead to remote code execution if a suitable POSt gadget chain exists. The weakness is classified as CWE-502.
Affected Systems
The affected product is b2evolution CMS, versions 6.7.8 through 7.2.5. All releases in this range lack the necessary check to reject negative integer array keys, so any site running these versions is vulnerable.
Risk and Exploitability
The CVSS score of 9.2 places this flaw in the critical severity range. EPSS information is not available, so the current exploitation probability cannot be quantified. The attack vector is likely an unauthenticated HTTP POST to htsrv/call_plugin.php, a publicly reachable endpoint, which indicates a low barrier to exploitation. Although the vulnerability is not listed in CISA’s KEV catalog, its potential for arbitrary code execution if a gadget chain can be assembled remains high.
OpenCVE Enrichment