What the vulnerability does
01Description
Deserialization of Untrusted Data vulnerability in Kalli Dan. KD Coming Soon.This issue affects KD Coming Soon: from n/a through 1.7.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:N
What the vulnerability does
Deserialization of Untrusted Data vulnerability in Kalli Dan. KD Coming Soon.This issue affects KD Coming Soon: from n/a through 1.7.
Explanation of Vulnerability in Simple Terms
KD Coming Soon versions up to 1.7 contain a deserialization flaw that allows an attacker to send malicious serialized data over the network. This can lead to unauthorized information disclosure or modification of site data. The attack requires specific conditions to succeed but does not require authentication or user interaction.
What an attacker can do
Read or modify sensitive site data by sending crafted serialized objects to the application.
Potential impact on your site
Unauthorized access to or modification of site data without requiring a user account or victim action.
Conditions required to exploit
Network access to the application; specific attack conditions must be met (high complexity).
Key dates
External resources
Related vulnerabilities