CVE-2022-47083
HIGHSpitfire CMS <1.0.475 - Code Injection
Title source: llmDescription
A PHP Object Injection vulnerability in the unserialize() function Spitfire CMS v1.0.475 allows authenticated attackers to execute arbitrary code via sending crafted requests to the web application.
Scores
CVSS v3
8.8
EPSS
0.0094
EPSS Percentile
76.0%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Classification
CWE
CWE-502
Status
published
Affected Products (1)
spitfire_project/spitfire
Timeline
Published
Jan 10, 2023
Tracked Since
Feb 18, 2026