What the vulnerability does
01Description
Editor PHP Object Injection in Car Rental Manager <= 1.3.9 versions.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
What the vulnerability does
Editor PHP Object Injection in Car Rental Manager <= 1.3.9 versions.
Explanation of Vulnerability in Simple Terms
Car Rental Manager versions up to 1.3.9 contain a deserialization vulnerability that allows authenticated administrators to execute arbitrary code on the site. An attacker with admin privileges can craft malicious serialized data to trigger code execution. This requires high-level access but poses a critical risk if admin accounts are compromised or if untrusted administrators have access.
What an attacker can do
Run arbitrary code on the site with full privileges.
Potential impact on your site
A compromised admin account could lead to complete site takeover, data theft, or malware installation.
Conditions required to exploit
Attacker must have administrator-level access to the site.
Key dates
External resources
Related vulnerabilities