← Advisories

Spitfire CMS 1.0.475 (cms_backup_values) PHP Object Injection

High
Advisory ID
ZSL-2022-5720
Release Date
09 December 2022
Vendor
Affected Version
1.0.475
Tested On
nginx
Summary

Spitfire is a system to manage the content of webpages.

Description

The application is prone to a PHP Object Injection vulnerability due to the unsafe use of unserialize() function. A potential attacker, authenticated, could exploit this vulnerability by sending specially crafted requests to the web application containing malicious serialized input.

Proof of Concept
Disclosure Timeline
28.09.2022Vulnerability discovered.
28.09.2022Vendor contacted.
08.12.2022No response from the vendor.
09.12.2022Public security advisory released.
Credits
Vulnerability discovered by Gjoko Krstic
References
Changelog
09.12.2022Initial release
10.12.2022Added reference [1]
14.12.2022Added reference [2]
10.02.2023Added reference [3], [4], [5] and [6]
10.04.2023Added reference [7]