CVE-2020-12469

admin/blocks.php in Subrion CMS through 4.2.1 allows PHP Object Injection (with resultant file deletion) via serialized data in the subpages value within a block to blocks/edit.
Configurations

Configuration 1

cpe:2.3:a:intelliants:subrion:*:*:*:*:*:*:*:*

Information

Published : 2020-04-29 09:15

Updated : 2020-05-05 04:28


NVD link : CVE-2020-12469

Mitre link : CVE-2020-12469

Products Affected
No products.
CWE
CWE-502

Deserialization of Untrusted Data