First published: Mon Nov 16 2015(Updated: )
The DisplayTopKeywords function in plugins/Referrers/Controller.php in Piwik before 2.15.0 allows remote attackers to conduct PHP object injection attacks, conduct Server-Side Request Forgery (SSRF) attacks, and execute arbitrary PHP code via a crafted HTTP header.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
MediaWiki Matomo | <=2.14.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-7816 is considered a high severity vulnerability due to the potential for PHP object injection and SSRF attacks.
To fix CVE-2015-7816, upgrade Piwik to version 2.15.0 or later.
CVE-2015-7816 can facilitate PHP object injection attacks and Server-Side Request Forgery (SSRF) attacks.
Piwik versions prior to 2.15.0, specifically up to 2.14.3, are affected by CVE-2015-7816.
Yes, CVE-2015-7816 can allow remote attackers to execute arbitrary PHP code via crafted HTTP headers.