EasyUse MailHunter Ultimate’s cookie deserialization...
Critical severity
Unreviewed
Published
Aug 3, 2022
to the GitHub Advisory Database
•
Updated Jan 27, 2023
Description
Published by the National Vulnerability Database
Aug 2, 2022
Published to the GitHub Advisory Database
Aug 3, 2022
Last updated
Jan 27, 2023
EasyUse MailHunter Ultimate’s cookie deserialization function has an inadequate validation vulnerability. Deserializing a cookie containing malicious payload will trigger this insecure deserialization vulnerability, allowing an unauthenticated remote attacker to execute arbitrary code, manipulate system command or interrupt service.
References