What the vulnerability does
01Description
Deserialization of Untrusted Data vulnerability in Edge-Themes Archicon archicon allows Object Injection.This issue affects Archicon: from n/a through < 1.7.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L
What the vulnerability does
Deserialization of Untrusted Data vulnerability in Edge-Themes Archicon archicon allows Object Injection.This issue affects Archicon: from n/a through < 1.7.
Explanation of Vulnerability in Simple Terms
Archicon versions before 1.7 contain a deserialization vulnerability in how they process untrusted data. An authenticated user can supply malicious serialized objects that execute unintended code or modify data when deserialized. This affects the integrity and availability of the site but does not expose sensitive information.
What an attacker can do
Modify site data or disrupt availability by submitting malicious serialized objects.
Potential impact on your site
Authenticated users can corrupt data or cause the site to malfunction without exposing passwords or private content.
Conditions required to exploit
Attacker must be authenticated with low-level user privileges and have network access to the site.
Key dates
External resources
Related vulnerabilities