CVE-2024-22284: WordPress Asgaros Forum Plugin <= 2.7.2 is vulnerable to PHP Object Injection
Published Jan 24, 2024
·Updated
Deserialization of Untrusted Data vulnerability in Thomas Belser Asgaros Forum.This issue affects Asgaros Forum: from n/a through 2.7.2.
Affected Software
1 affected component
Asgaros Asgaros Forum WordPress<2.8.0
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
wordpress/asgaros-forumto a version that resolves this vulnerability.Fixed in 2.8.0
Event History
Jan 24, 2024
CVE Published
via MITRE·11:45 AM
Data Sourced
via MITRE·11:45 AM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·12:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-22284?
The severity of CVE-2024-22284 is considered high due to the potential for remote code execution.
2
How do I fix CVE-2024-22284?
To fix CVE-2024-22284, upgrade Asgaros Forum to version 2.8.0 or later.
3
What versions of Asgaros Forum are affected by CVE-2024-22284?
CVE-2024-22284 affects all versions of Asgaros Forum up to and including 2.7.2.
4
Can CVE-2024-22284 lead to unauthorized access?
Yes, CVE-2024-22284 can potentially lead to unauthorized access through deserialization of untrusted data.
5
What type of vulnerability is CVE-2024-22284?
CVE-2024-22284 is a deserialization of untrusted data vulnerability.