Arbitrary Code Execution Affecting phpmussel/phpmussel package, versions >=1.0.0, <1.6.0


0.0
high

Snyk CVSS

    Attack Complexity Low
    Confidentiality High
    Integrity High
    Availability High

    Threat Intelligence

    EPSS 0.41% (74th percentile)
Expand this section
NVD
9.8 critical

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk ID SNYK-PHP-PHPMUSSELPHPMUSSEL-571994
  • published 11 Jun 2020
  • disclosed 11 Jun 2020
  • credit Unknown

How to fix?

Upgrade phpmussel/phpmussel to version 1.6.0 or higher.

Overview

phpmussel/phpmussel is a PHP-based anti-virus anti-trojan anti-malware solution.

Affected versions of this package are vulnerable to Arbitrary Code Execution due to an unserialization vulnerability in PHP's phar wrapper. Uploading a specially crafted file to an affected version allows arbitrary code execution.