Vulnerabilities > CVE-2022-47083 - Deserialization of Untrusted Data vulnerability in Spitfire Project Spitfire 1.0475

047910
CVSS 8.8 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
LOW
Confidentiality impact
HIGH
Integrity impact
HIGH
Availability impact
HIGH
network
low complexity
spitfire-project
CWE-502

Summary

A PHP Object Injection vulnerability in the unserialize() function Spitfire CMS v1.0.475 allows authenticated attackers to execute arbitrary code via sending crafted requests to the web application.

Vulnerable Configurations

Part Description Count
Application
Spitfire_Project
1

Common Weakness Enumeration (CWE)