A vulnerability in the sendMailFromRemoteSource method in Emails.php as used in Bitdefender GravityZone Console unsafely uses php unserialize() on user-supplied input without validation. By crafting a malicious serialized payload, an attacker can trigger PHP object injection, perform a file write, and gain arbitrary command execution on the host system.
Metrics
Affected Vendors & Products
References
History
Fri, 04 Apr 2025 15:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Fri, 04 Apr 2025 10:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | A vulnerability in the sendMailFromRemoteSource method in Emails.php as used in Bitdefender GravityZone Console unsafely uses php unserialize() on user-supplied input without validation. By crafting a malicious serialized payload, an attacker can trigger PHP object injection, perform a file write, and gain arbitrary command execution on the host system. | |
Title | Insecure PHP deserialization issue in GravityZone Console (VA-12634) | |
Weaknesses | CWE-502 | |
References |
| |
Metrics |
cvssV4_0
|

Status: PUBLISHED
Assigner: Bitdefender
Published:
Updated: 2025-04-04T14:26:11.160Z
Reserved: 2025-03-12T11:14:05.487Z
Link: CVE-2025-2244

Updated: 2025-04-04T14:26:06.449Z

Status : Awaiting Analysis
Published: 2025-04-04T10:15:16.580
Modified: 2025-04-07T14:18:15.560
Link: CVE-2025-2244

No data.