#VU27474 Deserialization of Untrusted Data in Subrion CMS - CVE-2020-12469
Published: April 30, 2020
Subrion CMS
Intelliants
Description
The vulnerability allows a remote attacker to delete arbitrary files.
The vulnerability exists in "admin/blocks.php" file due to insecure input validation when processing serialized data in the subpages value within a block to blocks/edit. A remote authenticated attacker can pass specially crafted data to the application, cause PHP Object Injection and delete arbitrary files on the target system.