Total vulnerabilities in the database
It has been discovered that the Form Framework (system extension form
) is vulnerable to Insecure Deserialization when being used with the additional PHP PECL package yaml
, which is capable of unserializing YAML contents to PHP objects. A valid backend user account as well as having PHP setting yaml.decode_php
enabled is needed to exploit this vulnerability (which is the default value according to PHP documentation).
Software | From | Fixed in |
---|---|---|
![]() |
8.5.0 | 8.7.17 |
![]() |
9.0.0 | 9.3.1 |