CakePHP Deserialization of Untrusted Data Vulnerability - CVE-2019-11458 - Vulnerability Database

CakePHP Deserialization of Untrusted Data Vulnerability - CVE-2019-11458

High
Reference: CVE-2019-11458
Title: CakePHP Deserialization of Untrusted Data Vulnerability
Overview:

An issue was discovered in SmtpTransport in CakePHP 3.7.6. An unserialized object with modified internal properties can trigger arbitrary file overwriting upon destruction.