Vulnerabilities > CVE-2018-1000509 - Deserialization of Untrusted Data vulnerability in Redirection 2.7.1

047910
CVSS 6.5 - MEDIUM
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
SINGLE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
PARTIAL
network
low complexity
redirection
CWE-502

Summary

Redirection version 2.7.1 contains a Serialisation vulnerability possibly allowing ACE vulnerability in Settings page AJAX that can result in could allow admin to execute arbitrary code in some circumstances. This attack appear to be exploitable via Attacker must have access to admin account. This vulnerability appears to have been fixed in 2.8.

Vulnerable Configurations

Part Description Count
Application
Redirection
1

Common Weakness Enumeration (CWE)