Beveiligingsadvies

CVE-2026-91939

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2026-09-15 20:56:45
Laatst bijgewerkt 2026-09-15 20:56:45
Toegewezen door VulnCheck
CVSS-score 9.8
Status PUBLISHED

Beschrijving

Cotonti 1.0.0 Comments plugin passes the ci GET parameter to unserialize() without allowed_classes restriction, allowing unauthenticated attackers to instantiate arbitrary PHP classes with attacker-controlled properties. Attackers can exploit PHP object injection through crafted serialized payloads to trigger gadget chains and achieve database manipulation or code execution.