What the vulnerability does
01Description
Deserialization of Untrusted Data vulnerability in Mikado-Themes Halstein halstein allows Object Injection.This issue affects Halstein: from n/a through < 1.8.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L
What the vulnerability does
Deserialization of Untrusted Data vulnerability in Mikado-Themes Halstein halstein allows Object Injection.This issue affects Halstein: from n/a through < 1.8.
Explanation of Vulnerability in Simple Terms
Halstein versions before 1.8 contain a deserialization vulnerability that allows authenticated users to modify site data. An attacker with low-level access can send specially crafted requests to trigger unsafe deserialization, compromising data integrity. Update to version 1.8 or later to resolve this issue.
What an attacker can do
Modify site data or cause the site to malfunction by sending malicious serialized objects.
Potential impact on your site
Authenticated users can corrupt or alter site content and functionality without authorization.
Conditions required to exploit
Attacker must have a low-privilege user account on the site; no user interaction required.
Key dates
External resources
Related vulnerabilities