Deserialization of Untrusted Data of the __post_data parameter in cn_parse_url() in CuteNews v.2.1.2 allows a remote attacker to inject arbitrary values into internal request variables (including __r…
Medium CVSS 5.8
Summary
Deserialization of Untrusted Data of the __post_data parameter in cn_parse_url() in CuteNews v.2.1.2 allows a remote attacker to inject arbitrary values into internal request variables (including __referer) via a crafted base64-encoded serialized PHP payload submitted as a POST parameter.
In-depth triage
No in-depth report has been generated yet (DR-003 v2 AI pipeline is under construction).
Sources
- NVD DATABASE
Original Links
- https://github.com/CuteNews/cutenews-2.0
- https://github.com/CuteNews/cutenews-2.0/blob/master/core/core.php
- https://github.com/UmbraDeorum/cutenews-2.0-CVEs-2026-Disclosure
Timeline
- nvd_ingest NVD