CVE-2018-1000059

CRITICAL

ValidFormBuilder 4.5.4 - Code Injection

Title source: llm

Description

ValidFormBuilder version 4.5.4 contains a PHP Object Injection vulnerability in Valid Form unserialize method that can result in Possible to execute unauthorised system commands remotely and disclose file contents in file system.

Scores

CVSS v3 9.8
EPSS 0.0027
EPSS Percentile 49.8%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Classification

CWE
CWE-502
Status published

Affected Products (1)

validformbuilder/validform_builder

Timeline

Published Feb 09, 2018
Tracked Since Feb 18, 2026