Show plain JSON{"id": "CVE-2018-1000059", "metrics": {"cvssMetricV2": [{"type": "Primary", "source": "nvd@nist.gov", "cvssData": {"version": "2.0", "baseScore": 7.5, "accessVector": "NETWORK", "vectorString": "AV:N/AC:L/Au:N/C:P/I:P/A:P", "authentication": "NONE", "integrityImpact": "PARTIAL", "accessComplexity": "LOW", "availabilityImpact": "PARTIAL", "confidentialityImpact": "PARTIAL"}, "acInsufInfo": false, "impactScore": 6.4, "baseSeverity": "HIGH", "obtainAllPrivilege": false, "exploitabilityScore": 10.0, "obtainUserPrivilege": false, "obtainOtherPrivilege": false, "userInteractionRequired": false}], "cvssMetricV30": [{"type": "Primary", "source": "nvd@nist.gov", "cvssData": {"scope": "UNCHANGED", "version": "3.0", "baseScore": 9.8, "attackVector": "NETWORK", "baseSeverity": "CRITICAL", "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H", "integrityImpact": "HIGH", "userInteraction": "NONE", "attackComplexity": "LOW", "availabilityImpact": "HIGH", "privilegesRequired": "NONE", "confidentialityImpact": "HIGH"}, "impactScore": 5.9, "exploitabilityScore": 3.9}]}, "published": "2018-02-09T23:29:02.167", "references": [{"url": "https://github.com/validformbuilder/validformbuilder/issues/126", "tags": ["Issue Tracking", "Third Party Advisory"], "source": "cve@mitre.org"}, {"url": "https://github.com/validformbuilder/validformbuilder/issues/126", "tags": ["Issue Tracking", "Third Party Advisory"], "source": "af854a3a-2127-422b-91ae-364da2661108"}], "vulnStatus": "Modified", "weaknesses": [{"type": "Primary", "source": "nvd@nist.gov", "description": [{"lang": "en", "value": "CWE-502"}]}], "descriptions": [{"lang": "en", "value": "ValidFormBuilder version 4.5.4 contains a PHP Object Injection vulnerability in Valid Form unserialize method that can result in Possible to execute unauthorised system commands remotely and disclose file contents in file system."}, {"lang": "es", "value": "ValidFormBuilder 4.5.4 contiene una vulnerabilidad de inyecci\u00f3n de objetos PHP en el m\u00e9todo de deserializaci\u00f3n Valid Form que puede resultar en la posibilidad de ejecuci\u00f3n de comandos del sistema sin autorizaci\u00f3n de forma remota y la revelaci\u00f3n del contenido de archivos en el sistema de archivos."}], "lastModified": "2024-11-21T03:39:33.097", "configurations": [{"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:a:validformbuilder:validform_builder:4.5.4:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "0E026F6E-35F8-472A-89E0-23979B828921"}], "operator": "OR"}]}], "sourceIdentifier": "cve@mitre.org"}