CVE-2023-46817
CRITICALphpFox <4.8.14 - Code Injection
Title source: llmDescription
An issue was discovered in phpFox before 4.8.14. The url request parameter passed to the /core/redirect route is not properly sanitized before being used in a call to the unserialize() PHP function. This can be exploited by remote, unauthenticated attackers to inject arbitrary PHP objects into the application scope, allowing them to perform a variety of attacks, such as executing arbitrary PHP code.
References (5)
Scores
CVSS v3
9.8
EPSS
0.0077
EPSS Percentile
73.2%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Classification
CWE
CWE-502
Status
published
Affected Products (1)
phpfox/phpfox
< 4.8.13
Timeline
Published
Nov 03, 2023
Tracked Since
Feb 18, 2026