luracast/restler is vulnerable to Deserialization of Untrusted Data
85
High Risk
Affected versions of this package are vulnerable to Insecure Deserialization, where session data was processed using PHP's serialize() and unserialize() functions without proper validation, allowing attackers to inject malicious objects via crafted serialized strings that, when deserialized, could lead to arbitrary code execution or session manipulation.
You are affected if you are using a version that falls within the vulnerable range.
luracast/restler is vulnerable to Deserialization of Untrusted Data in versions 5.0.0 - 5.0.13.
Upgrade the luracast/restler library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant