Ecosyste.ms: Advisories
An open API service providing security vulnerability metadata for many open source software ecosystems.
Security Advisories: GSA_kwCzR0hTQS0ycDJ4LW13NTYtamM5OM4AAh4I
Spoon Library as used in Fork CMS allows PHP object injection
Spoon Library through 2014-02-06, as used in Fork CMS before 1.4.1 and other products, allows PHP object injection via a cookie containing an object.
Permalink: https://github.com/advisories/GHSA-2p2x-mw56-jc98JSON: https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS0ycDJ4LW13NTYtamM5OM4AAh4I
Source: GitHub Advisory Database
Origin: Unspecified
Severity: Critical
Classification: General
Published: almost 2 years ago
Updated: 10 months ago
CVSS Score: 9.8
CVSS vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Identifiers: GHSA-2p2x-mw56-jc98, CVE-2019-15521
References:
- https://nvd.nist.gov/vuln/detail/CVE-2019-15521
- https://github.com/forkcms/library/pull/69
- https://github.com/forkcms/library/releases/tag/1.4.1
- https://github.com/spoon/library/blob/bda89be80b7e1ffdc93d3180d33a56927430298b/spoon/cookie/cookie.php#L117
- https://github.com/advisories/GHSA-2p2x-mw56-jc98
Blast Radius: 13.5
Affected Packages
packagist:spoon/library
Dependent packages: 1Dependent repositories: 24
Downloads: 244,698 total
Affected Version Ranges: < 1.4.1
Fixed in: 1.4.1
All affected versions: 1.3.1, 1.3.2, 1.3.3, 1.3.4, 1.3.5, 1.3.6, 1.3.7, 1.3.8, 1.3.9, 1.3.10, 1.3.11, 1.3.12, 1.3.13, 1.3.14, 1.3.15, 1.3.16, 1.3.17, 1.3.18, 1.4.0
All unaffected versions: 1.4.1, 1.4.2, 1.4.3, 1.4.4, 1.4.5, 2.0.1, 2.0.2, 2.0.3, 2.0.4, 2.0.5, 2.0.6, 2.0.7, 2.1.0, 2.2.0, 2.2.1, 2.2.2, 2.2.3, 2.2.4, 2.3.0, 2.3.1, 2.3.2, 2.3.3, 2.3.4, 2.3.5, 2.3.6, 2.3.7, 2.3.8, 2.3.9, 2.3.10, 3.0.0, 3.0.1, 3.0.2, 3.0.3, 3.0.4, 3.1.0, 3.1.1, 3.2.0, 3.2.1, 3.2.2, 3.2.3, 3.2.4, 3.2.5, 3.2.6, 3.2.7, 3.2.8, 3.2.9, 3.2.10, 3.2.11, 3.2.12