CVE-2023-46817
This can be exploited by remote, unauthenticated attackers to inject arbitrary PHP objects into the application scope, allowing them to perform a variety of attacks, such as executing arbitrary PHP code.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (1.81%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
An issue was discovered in phpFox before 4.8.14. The url request parameter passed to the /core/redirect route is not properly sanitized before being used in a call to the unserialize() PHP function. This can be exploited by remote, unauthenticated attackers to inject arbitrary PHP objects into the application scope, allowing them to perform a variety of attacks, such as executing arbitrary PHP code.
- CVSS 3.1
- 9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 1.81% probability · 77th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-502
- Affected
- phpfox/phpfox
- Source
- cve@mitre.org
References
- http://seclists.org/fulldisclosure/2023/Oct/30Exploit, Mailing List, Third Party Advisory
- https://docs.phpfox.com/display/FOX4MAN/phpFox+4.8.14Product
- https://karmainsecurity.com/KIS-2023-12Third Party Advisory
- https://karmainsecurity.com/pocs/CVE-2023-46817.phpExploit, Third Party Advisory
- https://www.phpfox.com/blog/Product
- http://seclists.org/fulldisclosure/2023/Oct/30Exploit, Mailing List, Third Party Advisory
- https://docs.phpfox.com/display/FOX4MAN/phpFox+4.8.14Product
- https://karmainsecurity.com/KIS-2023-12Third Party Advisory
- https://karmainsecurity.com/pocs/CVE-2023-46817.phpExploit, Third Party Advisory
- https://www.phpfox.com/blog/Product
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.