What the vulnerability does
01Description
Deserialization of Untrusted Data vulnerability in NooTheme Organici Library noo-organici-library allows Object Injection.This issue affects Organici Library: from n/a through <= 2.1.2.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
What the vulnerability does
Deserialization of Untrusted Data vulnerability in NooTheme Organici Library noo-organici-library allows Object Injection.This issue affects Organici Library: from n/a through <= 2.1.2.
Explanation of Vulnerability in Simple Terms
Organici Library versions up to 2.1.2 contain a deserialization vulnerability that allows authenticated attackers to execute arbitrary code on the server. The library unsafely deserializes untrusted data without proper validation. An attacker with low-level access can craft malicious serialized objects to achieve remote code execution with full system privileges.
What an attacker can do
Run arbitrary code on the server with full system access.
Potential impact on your site
Complete server compromise; attacker can read, modify, or delete all site data and files.
Conditions required to exploit
Attacker must have low-level authenticated access to the application.
Key dates
External resources
Related vulnerabilities