CVE-2020-4043
HIGHPhpmussel < 1.6.0 - Insecure Deserialization
Title source: ruleDescription
phpMussel from versions 1.0.0 and less than 1.6.0 has an unserialization vulnerability in PHP's phar wrapper. Uploading a specially crafted file to an affected version allows arbitrary code execution (discovered, tested, and confirmed by myself), so the risk factor should be regarded as very high. Newer phpMussel versions don't use PHP's phar wrapper, and are therefore unaffected. This has been fixed in version 1.6.0.
Scores
CVSS v3
7.7
EPSS
0.0157
EPSS Percentile
81.3%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:N
Classification
CWE
CWE-502
Status
published
Affected Products (3)
phpmussel_project/phpmussel
< 1.6.0
phpmussel/phpmussel
< 1.6.0Packagist
maikuolan/phpmussel
< 1.6.0Packagist
Timeline
Published
Jun 10, 2020
Tracked Since
Feb 18, 2026