CVE-2022-39297 Information
Oct 13, 2022
cve
Description
MelisCms provides a full CMS for Melis Platform including templating system drag’n’drop of plugins SEO and many administration tools. Attackers can deserialize arbitrary data on affected versions of melisplatform/melis-cms and ultimately leads to the execution of arbitrary PHP code on the system. Conducting this attack does not require authentication. Users should immediately upgrade to melisplatform/melis-cms >= 5.0.1. This issue was addressed by restricting allowed classes when deserializing user-controlled data.
Reference
https://github.com/melisplatform/melis-cms/commit/d124b2474699a679a24ec52620cadceb3d4cec11 https://github.com/melisplatform/melis-cms/security/advisories/GHSA-m3m3-6gww-7gj9
Share on: