Blesta Object Injection Vulnerability Allowing Potential Remote Code Execution
Vulnerability
An object injection vulnerability has been identified in Blesta versions 3.x through 5.x prior to 5.13.3. This vulnerability, referenced as CORE-5680, could potentially allow remote code execution under certain conditions.
Impact
Exploitation of this vulnerability could lead to object injection, with the possibility of remote code execution.
Remediation
Users are advised to upgrade to Blesta version 5.13.3. Instructions for upgrading and patching existing installations are available in the Blesta user manual. For those using an affected unsupported version of Blesta (between 3.0 and 5.10), it is recommended to upgrade as soon as possible.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
