What the vulnerability does
01Description
Deserialization of Untrusted Data vulnerability in reputeinfosystems ARPrice arprice allows Object Injection.This issue affects ARPrice: from n/a through <= 4.1.3.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
What the vulnerability does
Deserialization of Untrusted Data vulnerability in reputeinfosystems ARPrice arprice allows Object Injection.This issue affects ARPrice: from n/a through <= 4.1.3.
Explanation of Vulnerability in Simple Terms
ARPrice versions up to 4.1.3 contain a deserialization vulnerability that allows authenticated attackers to execute arbitrary code on the server. The flaw exists in how the application processes untrusted serialized data without proper validation. An attacker with low-level access can craft malicious input to trigger code execution with full system privileges.
What an attacker can do
Run their own code on the server with full system access (remote code execution).
Potential impact on your site
Complete compromise of the server; attacker can read, modify, or delete all data and install backdoors.
Conditions required to exploit
Attacker must have a low-level user account or authenticated session on the application.
Key dates
External resources
Related vulnerabilities