CVE-2019-19373

An issue was discovered in Squiz Matrix CMS 5.5.0 prior to 5.5.0.3, 5.5.1 prior to 5.5.1.8, 5.5.2 prior to 5.5.2.4, and 5.5.3 prior to 5.5.3.3 where a user can trigger arbitrary unserialization of a PHP object from a packages/cms/page_templates/page_remote_content/page_remote_content.inc POST parameter during processing of a Remote Content page type. This unserialization can be used to trigger the inclusion of arbitrary files on the filesystem (local file inclusion), and results in remote code execution.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:squiz:matrix:*:*:*:*:*:*:*:*
cpe:2.3:a:squiz:matrix:*:*:*:*:*:*:*:*
cpe:2.3:a:squiz:matrix:*:*:*:*:*:*:*:*
cpe:2.3:a:squiz:matrix:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2019-12-11 20:15

Updated : 2023-12-10 13:13


NVD link : CVE-2019-19373

Mitre link : CVE-2019-19373

CVE.ORG link : CVE-2019-19373


JSON object : View

Products Affected

squiz

  • matrix
CWE
CWE-502

Deserialization of Untrusted Data