7.5
CVSSv2

CVE-2014-5297

Published: 10/10/2014 Updated: 09/10/2018
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

The actionSendErrorReport method in protected/controllers/SiteController.php in X2Engine 2.8 up to and including 4.1.7 allows remote malicious users to conduct PHP object injection and Server-Side Request Forgery (SSRF) attacks via crafted serialized data in the report parameter.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

x2engine x2engine 4.1.7

x2engine x2engine 2.8

Exploits

X2Engine versions 28 through 417 suffer from a PHP object injection vulnerability ...