What the vulnerability does
01Description
Deserialization of Untrusted Data vulnerability in supsystic Popup by Supsystic popup-by-supsystic allows Command Injection.This issue affects Popup by Supsystic: from n/a through <= 1.10.29.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
What the vulnerability does
Deserialization of Untrusted Data vulnerability in supsystic Popup by Supsystic popup-by-supsystic allows Command Injection.This issue affects Popup by Supsystic: from n/a through <= 1.10.29.
Explanation of Vulnerability in Simple Terms
Popup by Supsystic versions 1.10.29 and earlier contain a vulnerability that allows high-privileged users to modify site configuration and data across the entire installation. An attacker with admin or equivalent access can read sensitive information, alter site content, and disrupt service. The vulnerability requires administrative credentials to exploit.
What an attacker can do
Read sensitive data, modify site configuration, and disrupt service availability across the entire installation.
Potential impact on your site
A compromised admin account can be used to alter your site's core settings, access user data, and cause downtime.
Conditions required to exploit
Attacker must have high-level administrative privileges (admin or equivalent role) on the site.
Key dates
External resources
Related vulnerabilities