Description
CraftCMS 3 vCard Plugin 1.0.0 contains a deserialization vulnerability that allows unauthenticated attackers to execute arbitrary PHP code through a crafted payload. Attackers can generate a malicious serialized payload that triggers remote code execution by exploiting the plugin's vCard download functionality with a specially crafted request.
Problem types
Deserialization of Untrusted Data
Product status
Credits
Wade Guest
References
www.exploit-db.com/exploits/48492 (ExploitDB-48492)
craftcms.com/ (Official CraftCMS Vendor Homepage)
plugins.craftcms.com/vcard (CraftCMS vCard Plugin Page)
gitlab.com/wguest/craftcms-vcard-exploit (Researcher Exploit Disclosure)
www.vulncheck.com/...tcms-vcard-plugin-remote-code-execution (VulnCheck Advisory: CraftCMS 3 vCard Plugin 1.0.0 - Remote Code Execution)