top of page
perceptive_background_267k.jpg

Unsafe deserialization vulnerability in MixPHP Framework 2.x thru 2.2.17. The session and cache handlers use unserialize() on data from the filesystem in the Fi…

Published:

30 april 2026 om 22:00:00

Alert date:

1 mei 2026 om 20:05:47

Source:

nvd.nist.gov

Click to open the original link from this advisory

Web Technologies

A critical unsafe deserialization vulnerability affects MixPHP Framework versions 2.x through 2.2.17. The vulnerability exists in the session and cache handlers which use unserialize() function on data retrieved from the filesystem through the FileHandler object. This type of vulnerability can potentially allow attackers to execute arbitrary code by manipulating serialized data. The issue affects multiple versions of the popular PHP framework, making it a significant security concern for applications built on MixPHP. Organizations using affected versions should prioritize updating to a patched version.

Technical details

Mitigation steps:

Affected products:

MixPHP Framework

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Deze website toont informatie afkomstig van externe bronnen; Perceptive aanvaardt geen verantwoordelijkheid voor de juistheid, volledigheid of actualiteit van deze informatie.

bottom of page