What the vulnerability does
01Description
Deserialization of Untrusted Data vulnerability in CodeSolz Better Find and Replace.This issue affects Better Find and Replace: from n/a through 1.6.1.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H
What the vulnerability does
Deserialization of Untrusted Data vulnerability in CodeSolz Better Find and Replace.This issue affects Better Find and Replace: from n/a through 1.6.1.
Explanation of Vulnerability in Simple Terms
Better Find and Replace versions up to 1.6.1 contain a deserialization vulnerability that allows attackers to execute arbitrary code on the site. An attacker can craft a malicious serialized object that, when processed by the plugin, runs their own PHP code. The attack requires user interaction—a site administrator must be tricked into performing an action that triggers the deserialization.
What an attacker can do
Run arbitrary PHP code on the site and take full control of it.
Potential impact on your site
Complete site compromise if an admin is socially engineered into interacting with attacker-controlled data.
Conditions required to exploit
Network access and user interaction; a site admin must trigger the vulnerable code path.
Key dates
External resources
Related vulnerabilities