What the vulnerability does
01Description
Deserialization of Untrusted Data vulnerability in Edge-Themes Gracey gracey allows Object Injection.This issue affects Gracey: from n/a through < 1.4.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L
What the vulnerability does
Deserialization of Untrusted Data vulnerability in Edge-Themes Gracey gracey allows Object Injection.This issue affects Gracey: from n/a through < 1.4.
Explanation of Vulnerability in Simple Terms
Gracey versions before 1.4 contain a deserialization vulnerability that allows authenticated users to modify site data. An attacker with low-level access can send malicious serialized objects to trigger unintended behavior, affecting both data integrity and availability. Update to version 1.4 or later to resolve this issue.
What an attacker can do
Modify site data or cause the site to become unavailable.
Potential impact on your site
Authenticated users can corrupt data or disrupt site functionality without admin privileges.
Conditions required to exploit
Attacker must have a low-level user account on the site.
Key dates
External resources
Related vulnerabilities