PHP object injection in the Ajax endpoint of the backend in ForkCMS below version 5.8.3 allows an authenticated remote user to execute malicious code.
Source: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-24036
Reference (s):
- FULLDISC:20210312 [AIT-SA-20210215-04] CVE-2020-24036: ForkCMS PHP Object Injection
- URL: http://seclists.org/fulldisclosure/2021/Mar/31
- http://forkcms.com
- http://packetstormsecurity.com/files/161764/ForkCMS-PHP-Object-Injection.html
- https://tech.feedyourhead.at/content/ForkCMS-PHP-Object-Injection-CVE-2020-24036