CVE-2019-15521

CRITICAL

Spoon-library Spoon Library < 2014-02-06 - Insecure Deserialization

Title source: rule

Description

Spoon Library through 2014-02-06, as used in Fork CMS before 1.4.1 and other products, allows PHP object injection via a cookie containing an object.

Scores

CVSS v3 9.8
EPSS 0.0068
EPSS Percentile 71.3%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Classification

CWE
CWE-502
Status published

Affected Products (3)

spoon-library/spoon_library < 2014-02-06
fork-cms/fork_cms < 1.4.1
spoon/library < 1.4.1Packagist

Timeline

Published Aug 26, 2019
Tracked Since Feb 18, 2026