What the vulnerability does
01Description
Deserialization of Untrusted Data vulnerability in Mikado-Themes Stål stal allows Object Injection.This issue affects Stål: from n/a through < 1.7.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L
What the vulnerability does
Deserialization of Untrusted Data vulnerability in Mikado-Themes Stål stal allows Object Injection.This issue affects Stål: from n/a through < 1.7.
Explanation of Vulnerability in Simple Terms
Stål versions before 1.7 contain a deserialization vulnerability that allows authenticated users to modify site data. An attacker with low-level access can craft malicious serialized objects to alter content or functionality. The vulnerability requires valid login credentials but no additional user interaction. Update to version 1.7 or later to resolve this issue.
What an attacker can do
Modify site data or functionality by submitting malicious serialized objects.
Potential impact on your site
Authenticated users can alter site content or behavior without authorization.
Conditions required to exploit
Attacker must have a valid user account with low-level privileges.
Key dates
External resources
Related vulnerabilities