Description
Deserialization of Untrusted Data vulnerability in designthemes Knowledge Base kbase allows Object Injection.This issue affects Knowledge Base: from n/a through <= 2.9.
Problem types
Deserialization of Untrusted Data
Product status
Any version
Credits
Tran Nguyen Bao Khanh (VCI - VNPT Cyber Immunity) (Patchstack Alliance)
References
vdp.patchstack.com/...2-9-php-object-injection-vulnerability