enituretechnology LTL Freight Quotes - TQL Edition
cpe:2.3:a:eniture:ltl_freight_quotes:*:*:*:*:wordpress:*:*
- <= 1.2.6
A deserialization vulnerability allowing PHP object injection has been identified in the Eniture Technology LTL Freight Quotes - TQL Edition plugin, affecting versions through 1.2.6. This vulnerability arises from the deserialization of untrusted data, which could potentially be exploited to inject objects that may lead to various types of code execution or manipulation, depending on the presence of a suitable object injection chain.
Exploitation of this vulnerability could allow for PHP object injection, which could be leveraged to execute code, perform SQL injection, traverse directories in an unauthorized manner, cause a denial-of-service condition, or other impacts, provided a suitable object injection chain is available.
Users of the Eniture Technology LTL Freight Quotes - TQL Edition plugin should update to version 1.2.7 or later to address this vulnerability.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.