What the vulnerability does
01Description
Deserialization of Untrusted Data vulnerability in EnvialoSimple EnvíaloSimple: Email Marketing y Newsletters.This issue affects EnvíaloSimple: Email Marketing y Newsletters: from n/a through 2.1.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
What the vulnerability does
Deserialization of Untrusted Data vulnerability in EnvialoSimple EnvíaloSimple: Email Marketing y Newsletters.This issue affects EnvíaloSimple: Email Marketing y Newsletters: from n/a through 2.1.
Explanation of Vulnerability in Simple Terms
EnvíaloSimple Email Marketing and Newsletters versions up to 2.1 contain a deserialization vulnerability that allows attackers to execute arbitrary code on the site. An attacker can craft a malicious serialized object that, when processed by the application, runs their own PHP code. The vulnerability requires user interaction—typically a victim must visit a malicious link or page—but can affect the entire site and any connected systems.
What an attacker can do
Run their own code on the site and compromise user data, site content, and availability.
Potential impact on your site
Complete site compromise, data theft, malware injection, and potential lateral movement to connected systems.
Conditions required to exploit
Network access and user interaction (victim must visit attacker-controlled page or link).
Key dates
External resources
Related vulnerabilities