GHSA-xvr9-jr9p-grf3HighCVSS 8.8

PHP object injection in the Ajax endpoint of the backend in ForkCMS below version 5.8.3 allows an...

Published
May 24, 2022
Last Modified
July 5, 2026

🔗 CVE IDs covered (1)

📋 Description

PHP object injection in the Ajax endpoint of the backend in ForkCMS below version 5.8.3 allows an authenticated remote user to execute malicious code.

🔗 References (7)