includes/classes/ia.core.users.php in Subrion CMS 4.0.5 allows remote attackers to conduct PHP Object Injection attacks via crafted serialized data in a salt cookie in a login request.
| Software | From | Fixed in |
|---|---|---|
intelliants / subrion
|
4.0.5 | 4.0.5.x |