What the vulnerability does
01Description
Deserialization of Untrusted Data vulnerability in Elated-Themes Leroux leroux allows Object Injection.This issue affects Leroux: from n/a through < 1.4.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L
What the vulnerability does
Deserialization of Untrusted Data vulnerability in Elated-Themes Leroux leroux allows Object Injection.This issue affects Leroux: from n/a through < 1.4.
Explanation of Vulnerability in Simple Terms
Leroux versions before 1.4 contain a deserialization vulnerability that allows authenticated users to modify site data. An attacker with low-level access can supply malicious serialized objects to trigger unintended behavior. This affects data integrity and availability but does not expose sensitive information.
What an attacker can do
Modify or disrupt site data and functionality by submitting malicious serialized objects.
Potential impact on your site
Authenticated users can corrupt or disable site features; data integrity is at risk.
Conditions required to exploit
Attacker must have a low-level user account on the site; no user interaction required.
Key dates
External resources
Related vulnerabilities