What the vulnerability does
01Description
Deserialization of Untrusted Data vulnerability in TotalSuite TotalContest Lite totalcontest-lite allows Object Injection.This issue affects TotalContest Lite: from n/a through <= 2.9.1.
CVSS base score
What the vulnerability does
Deserialization of Untrusted Data vulnerability in TotalSuite TotalContest Lite totalcontest-lite allows Object Injection.This issue affects TotalContest Lite: from n/a through <= 2.9.1.
Explanation of Vulnerability in Simple Terms
TotalContest Lite versions 2.9.1 and earlier contain a deserialization vulnerability that allows attackers to execute arbitrary code by sending specially crafted serialized data. The vulnerability exists in how the plugin processes untrusted input without proper validation. Successful exploitation requires network access but the exact attack prerequisites are unclear due to incomplete CVSS data.
What an attacker can do
Execute arbitrary code on the site by sending malicious serialized data to the plugin.
Potential impact on your site
An attacker could run their own code on your site, potentially compromising user data, modifying content, or taking full control.
Conditions required to exploit
Network access to the vulnerable plugin; specific authentication or user interaction requirements unknown.
Key dates
External resources
Related vulnerabilities