What the vulnerability does
01Description
Deserialization of Untrusted Data vulnerability in ThemeGoods Photography photography allows Object Injection.This issue affects Photography: from n/a through <= 7.7.2.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H
What the vulnerability does
Deserialization of Untrusted Data vulnerability in ThemeGoods Photography photography allows Object Injection.This issue affects Photography: from n/a through <= 7.7.2.
Explanation of Vulnerability in Simple Terms
ThemeGoods Photography versions up to 7.7.2 contain a deserialization vulnerability that allows unauthenticated attackers to execute arbitrary code on the site. The vulnerability requires specific network conditions but can compromise the entire server, including data confidentiality, integrity, and availability. Site administrators should update immediately to a patched version.
What an attacker can do
Run arbitrary code on the site server without authentication, potentially compromising all data and functionality.
Potential impact on your site
Complete server compromise possible: attackers can read/modify all data, install backdoors, or take the site offline.
Conditions required to exploit
Network access to the site; no authentication or user interaction required, though exploitation requires specific network conditions.
Key dates
External resources
Related vulnerabilities