Page tree
Skip to end of metadata
Go to start of metadata

You are viewing an old version of this page. View the current version.

Compare with Current View Page History

« Previous Version 3 Current »

What's new

ID

Description

1Fix security issue CVE-2023-46817

Issue Summary

The URL request parameter passed to the /core/redirect route is not properly sanitized before being used in a call to the unserialize() PHP function.

This can be exploited by remote, unauthenticated attackers to inject arbitrary PHP objects into the application scope, allowing them to perform a variety of attacks, such as executing arbitrary PHP code.

  • No labels