Horizon Alert
Summary of the vulnerability and why it matters
This advisory addresses a critical security flaw found in b2evolution CMS, a content management system. The vulnerability allows unauthenticated attackers to execute arbitrary code by submitting specially crafted data, potentially impacting any organization using the affected versions. The primary concern is to confirm if this technology is in use and assess any potential exposure.
- Attackers can run any code on affected systems.
- Critical flaw impacts a common web content platform.
- Confirm relevance and investigate exposure risks.
Attack Path
How an attacker could exploit the issue
An attacker could target this vulnerability by sending specially crafted POST requests to the `htsrv/call_plugin.php` endpoint. This allows unauthenticated attackers to bypass security checks by submitting serialized PHP objects with negative integer array keys. If suitable chains of code exist, this could lead to the instantiation of arbitrary PHP objects, potentially enabling arbitrary code execution.
- Attacker sends POST request to vulnerable endpoint.
- Malicious serialized objects bypass validation.
- Risk of arbitrary code execution.
Live Threat
Current exploitation, exposure, and threat context
This vulnerability could affect the integrity and availability of a b2evolution CMS. When supported by the advisory, an unauthenticated attacker could submit specially crafted POST requests to a plugin endpoint, bypassing validation and potentially executing arbitrary PHP code by instantiating chosen objects. This could occur when the affected CMS is configured to allow unauthenticated access to the `htsrv/call_plugin.php` endpoint.
- System data and service behavior.
- Crafted POST requests bypass validation.
- Potential for arbitrary code execution.
Operational Fix
Recommended remediation, mitigation, and detection steps
System owners responsible for b2evolution CMS deployments must first locate all instances of the affected software, verify its external reachability and business criticality, and identify the accountable application owner. Remediation planning should then be prioritized based on these findings.
- Application owners should manage the issue.
- Verify external reachability and business criticality.
- Plan remediation based on identified risk.