Object Injection Vulnerability in Simple Login Log by Max Chirkov
CVE-2025-49438
7.2HIGH
What is CVE-2025-49438?
A deserialization of untrusted data vulnerability exists in the Simple Login Log plugin developed by Max Chirkov, allowing for potential object injection attacks. This vulnerability could enable an attacker to execute arbitrary code or achieve unauthorized access by manipulating serialized objects. Users of affected versions, specifically from n/a through 1.1.3, are strongly advised to apply necessary updates and implement security best practices to mitigate potential risks.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Simple Login Log <= 1.1.3
References
CVSS V3.1
Score:
7.2
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
mcdruid (Patchstack Alliance)