Deserialization of Untrusted Data Vulnerability Affects Participants Database
CVE-2024-43141
9.8CRITICAL
Summary
An identified vulnerability pertaining to the Participants Database plugin, developed by Roland Barker, exposes systems to the risk of object injection due to the deserialization of untrusted data. This vulnerability impacts versions from an unspecified release through 2.5.9.2, enabling potential attackers to exploit the affected system. Proper mitigation measures should be considered to safeguard against this flaw, as it may allow the execution of arbitrary PHP code leading to unauthorized access and manipulation of the database.
Affected Version(s)
Participants Database <= 2.5.9.2
References
CVSS V3.1
Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
LVT-tholv2k (Patchstack Alliance)