Insecure Deserialization in MiczFlor RPi-Jukebox-RFID Project
CVE-2025-63951
What is CVE-2025-63951?
The MiczFlor RPi-Jukebox-RFID project contains an insecure deserialization vulnerability in its rss-mp3.php script. Specifically, the application processes the 'rss' GET parameter using the unserialize() function without proper input validation. This vulnerability allows remote, unauthenticated attackers to inject malicious PHP objects into the application. Consequently, this can result in unexpected behavior, including application errors and potential denial of service. It is essential for users to be aware of this flaw and take necessary measures to mitigate the risk.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved
