What the vulnerability does
01Description
Deserialization of Untrusted Data vulnerability in sunshinephotocart Sunshine Photo Cart sunshine-photo-cart.This issue affects Sunshine Photo Cart: from n/a through <= 3.1.1.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:N
What the vulnerability does
Deserialization of Untrusted Data vulnerability in sunshinephotocart Sunshine Photo Cart sunshine-photo-cart.This issue affects Sunshine Photo Cart: from n/a through <= 3.1.1.
Explanation of Vulnerability in Simple Terms
Sunshine Photo Cart versions 3.1.1 and earlier contain a deserialization vulnerability in how they process untrusted data. An attacker can craft malicious serialized objects that, when processed by the application, lead to unauthorized data access or modification. The attack requires specific conditions to succeed but does not require authentication or user interaction.
What an attacker can do
Read or modify sensitive data on the site by sending a specially crafted network request.
Potential impact on your site
Attackers can access or alter site data without logging in, potentially compromising customer information or site integrity.
Conditions required to exploit
Network access to the vulnerable application; no authentication required.
Key dates
External resources
Related vulnerabilities