What the vulnerability does
01Description
Deserialization of Untrusted Data vulnerability in Arraytics Eventin wp-event-solution allows Object Injection.This issue affects Eventin: from n/a through <= 4.1.3.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
What the vulnerability does
Deserialization of Untrusted Data vulnerability in Arraytics Eventin wp-event-solution allows Object Injection.This issue affects Eventin: from n/a through <= 4.1.3.
Explanation of Vulnerability in Simple Terms
Eventin versions up to 4.1.3 contain a deserialization vulnerability that allows authenticated attackers to execute arbitrary code on the server. The vulnerability exists in how the application processes untrusted serialized data without proper validation. An attacker with low-level access can craft malicious input to trigger code execution with full system privileges.
What an attacker can do
Run their own code on the server, read/modify any data, or disable the site.
Potential impact on your site
Complete compromise of the Eventin installation and potentially the entire server.
Conditions required to exploit
Attacker must have a low-level user account or authenticated access to the application.
Key dates
External resources
Related vulnerabilities