CVE-2014-2293
Zikula Application Framework before 1.3.7 build 11 allows remote attackers to conduct PHP object injection attacks and delete arbitrary files or execute arbitrary PHP code via crafted serialized data in the (1) authentication_method_ser or (2)…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (4.67%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Zikula Application Framework before 1.3.7 build 11 allows remote attackers to conduct PHP object injection attacks and delete arbitrary files or execute arbitrary PHP code via crafted serialized data in the (1) authentication_method_ser or (2) authentication_info_ser parameter to index.php, or (3) zikulaMobileTheme parameter to index.php.
- CVSS 3.0
- 9.8 CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 4.67% probability · 91th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-94
- Affected
- zikula/zikula application framework
- Source
- cve@mitre.org
References
- http://karmainsecurity.com/KIS-2014-02Third Party Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/91786Third Party Advisory, VDB Entry
- https://exchange.xforce.ibmcloud.com/vulnerabilities/91787Third Party Advisory, VDB Entry
- https://secuniaresearch.flexerasoftware.com/secunia_research/2014-2/Third Party Advisory
- http://karmainsecurity.com/KIS-2014-02Third Party Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/91786Third Party Advisory, VDB Entry
- https://exchange.xforce.ibmcloud.com/vulnerabilities/91787Third Party Advisory, VDB Entry
- https://secuniaresearch.flexerasoftware.com/secunia_research/2014-2/Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.