Vanilla Forums Deserialization of Untrusted Data Vulnerability - CVE-2018-19499 - Vulnerability Database

Vanilla Forums Deserialization of Untrusted Data Vulnerability - CVE-2018-19499

High
Reference: CVE-2018-19499
Title: Vanilla Forums Deserialization of Untrusted Data Vulnerability
Overview:

Vanilla before 2.5.5 and 2.6.x before 2.6.2 allows Remote Code Execution because authenticated administrators have a reachable call to unserialize in the Gdn_Format class.