What the vulnerability does
01Description
Deserialization of Untrusted Data vulnerability in OCDI One Click Demo Import.This issue affects One Click Demo Import: from n/a through 3.2.0.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:L/I:L/A:N
What the vulnerability does
Deserialization of Untrusted Data vulnerability in OCDI One Click Demo Import.This issue affects One Click Demo Import: from n/a through 3.2.0.
Explanation of Vulnerability in Simple Terms
One Click Demo Import versions up to 3.2.0 contain a deserialization vulnerability that allows high-privilege users to trigger unintended code execution by supplying malicious serialized data. The attack requires administrator-level access and high attack complexity. Impact is limited to confidentiality and integrity of the affected system.
What an attacker can do
An admin user can supply malicious serialized data to read sensitive information or modify site data.
Potential impact on your site
If a compromised or malicious admin account exists, the site's data confidentiality and integrity are at risk.
Conditions required to exploit
Attacker must have administrator privileges and craft a specially formatted request with malicious serialized objects.
Key dates
External resources
Related vulnerabilities