Skip to content

Security: Insecure Deserialization via Cookie Values (CWE-502) #162

@Lexsec-dev

Description

@Lexsec-dev

Hi @MightyGorgon ,
unserialize() is called on $_COOKIE values without allowed_classes in multiple files (viewforum.php, viewtopic.php, forum.php, search.php, etc 25 instances). CWE-502. CVE IDs requested from MITRE.

Fix: add ['allowed_classes' false] or switch to json_decode().

Metadata

Metadata

Assignees

Labels

No labels
No labels

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions