What the vulnerability does
01Description
Deserialization of Untrusted Data vulnerability in Social Media Share Buttons By Sygnoos Social Media Share Buttons.This issue affects Social Media Share Buttons: from n/a through 2.1.0.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N
What the vulnerability does
Deserialization of Untrusted Data vulnerability in Social Media Share Buttons By Sygnoos Social Media Share Buttons.This issue affects Social Media Share Buttons: from n/a through 2.1.0.
Explanation of Vulnerability in Simple Terms
Social Media Share Buttons by Sygnoos versions up to 2.1.0 contain a deserialization vulnerability that allows authenticated attackers to execute arbitrary code on the site. The vulnerability requires low-level privileges and network access but no user interaction. Scope is changed, meaning the impact extends beyond the vulnerable component itself.
What an attacker can do
Run their own code on the site with the privileges of the authenticated user.
Potential impact on your site
Compromised site with potential data theft, malware injection, or defacement depending on attacker's account level.
Conditions required to exploit
Attacker must have a low-privilege account on the site; network access required.
Key dates
External resources
Related vulnerabilities