What the vulnerability does
01Description
Deserialization of Untrusted Data vulnerability in jetmonsters JetFormBuilder jetformbuilder allows Object Injection.This issue affects JetFormBuilder: from n/a through <= 3.5.1.2.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
What the vulnerability does
Deserialization of Untrusted Data vulnerability in jetmonsters JetFormBuilder jetformbuilder allows Object Injection.This issue affects JetFormBuilder: from n/a through <= 3.5.1.2.
Explanation of Vulnerability in Simple Terms
JetFormBuilder versions up to 3.5.1.2 contain a deserialization vulnerability that allows high-privileged users to execute arbitrary code on the site. An attacker with admin or equivalent access can craft malicious serialized data to trigger code execution. Update to version 3.6.3 or later to resolve this issue.
What an attacker can do
Run their own code on the site with full privileges.
Potential impact on your site
A compromised admin account can lead to complete site takeover and data theft.
Conditions required to exploit
Attacker must have high-level admin or equivalent access to the site.
Key dates
External resources
Related vulnerabilities