#VU48209 PHP Object Injection in Welcart e-Commerce - CVE-2020-28339
Published: November 7, 2020 / Updated: November 9, 2020
Welcart e-Commerce
Collne Inc.
Description
The vulnerability allows a remote attacker to execute arbitrary code on the target system.
The vulnerability exists due to the affected plugin unserialises the content of the "usces_cookie" cookie via "usces_unserialize()". A remote authenticated attacker can send a specially crafted request and execute arbitrary code on the target system.
Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.