AquilaCMS Deserialization Vulnerability in Categories API Endpoint

Vulnerability

A critical deserialization vulnerability has been identified in AquilaCMS version 1.412.13. The issue arises in the file '/api/v2/categories', where the 'PostBody.populate' argument can be manipulated, leading to unauthorized data deserialization. This vulnerability can be exploited remotely.

Impact

Exploitation of this vulnerability allows for deserialization of data, which could potentially be used to execute arbitrary code or manipulate application logic, depending on the deserialized data and the application's handling of it.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
7.5
exploitability
8.7
remediation
0.0
relevance
0.0
threat
6.4
urgency
2.9
incentive
5.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.