Vulnerabilities > CVE-2018-1000509 - Deserialization of Untrusted Data vulnerability in Redirection 2.7.1

047910
CVSS 7.2 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
HIGH
Confidentiality impact
HIGH
Integrity impact
HIGH
Availability impact
HIGH
network
low complexity
redirection
CWE-502

Summary

Redirection version 2.7.1 contains a Serialisation vulnerability possibly allowing ACE vulnerability in Settings page AJAX that can result in could allow admin to execute arbitrary code in some circumstances. This attack appear to be exploitable via Attacker must have access to admin account. This vulnerability appears to have been fixed in 2.8.

Vulnerable Configurations

Part Description Count
Application
Redirection
1

Common Weakness Enumeration (CWE)