CVE-2018-6195

HIGH

Splashing Images < 2.1.1 - Authenticated PHP Object Injection via Session Parameter

Title source: llm
STIX 2.1

Description

admin/partials/wp-splashing-admin-main.php in the Splashing Images plugin (wp-splashing-images) before 2.1.1 for WordPress allows authenticated (administrator, editor, or author) remote attackers to conduct PHP Object Injection attacks via crafted serialized data in the 'session' HTTP GET parameter to wp-admin/upload.php.

References (4)

Core 4
Core References
Exploit, Mailing List, Third Party Advisory mailing-list x_refsource_fulldisc
http://seclists.org/fulldisclosure/2018/Jan/91
Third Party Advisory x_refsource_misc
https://wpvulndb.com/vulnerabilities/9015

Scores

CVSS v3 7.2
EPSS 0.0374
EPSS Percentile 88.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-1321
Status published
Products (1)
splashing_images_project/splashing_images < 2.1.1
Published Jan 30, 2018
Tracked Since Feb 18, 2026