CVE-2022-35223
CRITICALEasyuse Mailhunter Ultimate < 2020 - Insecure Deserialization
Title source: ruleDescription
EasyUse MailHunter Ultimate’s cookie deserialization function has an inadequate validation vulnerability. Deserializing a cookie containing malicious payload will trigger this insecure deserialization vulnerability, allowing an unauthenticated remote attacker to execute arbitrary code, manipulate system command or interrupt service.
Scores
CVSS v3
9.8
EPSS
0.0345
EPSS Percentile
87.3%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Classification
CWE
CWE-502
Status
published
Affected Products (1)
easyuse/mailhunter_ultimate
< 2020
Timeline
Published
Aug 02, 2022
Tracked Since
Feb 18, 2026