CVE-2023-46817 Information

Description

An issue was discovered in phpFox before 4.8.14. The url request parameter passed to the /core/redirect route is not properly sanitized before being used in a call to the unserialize() PHP function. This can be exploited by remote unauthenticated attackers to inject arbitrary PHP objects into the application scope allowing them to perform a variety of attacks such as executing arbitrary PHP code.

Reference

https://karmainsecurity.com/KIS-2023-12 https://www.phpfox.com/blog/ https://karmainsecurity.com/pocs/CVE-2023-46817.php https://docs.phpfox.com/display/FOX4MAN/phpFox+4.8.14 http://seclists.org/fulldisclosure/2023/Oct/30 An issue was discovered in phpFox before 4.8.14. The url request parameter passed to the /core/redirect route is not properly sanitized before being used in a call to the unserialize() PHP function. This can be exploited by remote unauthenticated attackers to inject arbitrary PHP objects into the application scope allowing them to perform a variety of attacks such as executing arbitrary PHP code.

Share on: