Deserialization of Untrusted Data Vulnerability Affects INFINITUM FORM Geo Controller
CVE-2024-30227

9CRITICAL

Key Information:

Vendor
WordPress
Vendor
CVE Published:
28 March 2024

Summary

A vulnerability exists in the INFINITUM FORM Geo Controller, where deserialization of untrusted data can occur, potentially allowing attackers to exploit the system. This issue affects versions ranging from n/a to 8.6.4, making it critical for users of the Geo Controller to address this security concern to maintain the integrity of their systems.

Affected Version(s)

Geo Controller <= 8.6.4

References

CVSS V3.1

Score:
9
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

LVT-tholv2k (Patchstack Alliance)
.