wangl1989 mysiteforme
cpe:2.3:a:wangl1989:mysiteforme:*:*:*:*:*:*:*
- 1.0
A critical vulnerability allowing remote command execution has been identified in Wangl1989 MySiteForMe version 1.0. The issue arises in the 'rememberMeManager' function within 'src/main/java/com/mysiteforme/admin/config/ShiroConfig.java', where improper handling of data leads to deserialization vulnerabilities.
Exploitation of this vulnerability allows for remote command execution on the server where MySiteForMe is hosted.
The vulnerability can be reproduced by accessing the 'rememberMeManager' function, which inadvertently exposes a key that can be exploited for remote command execution. This can be done by sending a crafted request that takes advantage of the deserialization flaw.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.