CVE-2020-4043
Summary
| CVE | CVE-2020-4043 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2020-06-10 20:15:00 UTC |
| Updated | 2020-06-22 17:07:00 UTC |
| Description | phpMussel from versions 1.0.0 and less than 1.6.0 has an unserialization vulnerability in PHP's phar wrapper. Uploading a specially crafted file to an affected version allows arbitrary code execution (discovered, tested, and confirmed by myself), so the risk factor should be regarded as very high. Newer phpMussel versions don't use PHP's phar wrapper, and are therefore unaffected. This has been fixed in version 1.6.0. |
Risk And Classification
Problem Types: CWE-502
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Phpmussel Project | Phpmussel | All | All | All | All |
| Application | Phpmussel Project | Phpmussel | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Security Policy · phpMussel/phpMussel · GitHub | MISC | github.com | Third Party Advisory |
| Merge pull request #173 from phpMussel/archive-overhaul · phpMussel/phpMussel@97f2597 · GitHub | MISC | github.com | Patch, Release Notes, Third Party Advisory |
| Phar unserialization vulnerability · Advisory · phpMussel/phpMussel · GitHub | CONFIRM | github.com | Mitigation, Third Party Advisory |
| Phar unserialization vulnerability. · Issue #167 · phpMussel/phpMussel · GitHub | MISC | github.com | Patch, Third Party Advisory |
| Archive overhaul. by Maikuolan · Pull Request #173 · phpMussel/phpMussel · GitHub | MISC | github.com | Patch, Third Party Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.