open-dxp/opendxp is vulnerable to Insecure Deserialization
78
High Risk
Several session and temporary-data flows pass stored data straight into PHP's unserialize() without restricting which classes can be instantiated, covering the authentication session token, TmpStore entries, and a WebDAV delete-log restore path. Externally-influenced serialized content reaching any of these paths can instantiate arbitrary application classes, enabling PHP object injection through class magic methods. The fix introduces a SerializationScope allowlist that rejects classes outside a configured list and rejects incomplete classes, and adds explicit type checks on the restored value.
You are affected if you are using a version that falls within the vulnerable range and an externally-influenced value reaches the TmpStore-backed or session-token unserialize call.
open-dxp/opendxp is vulnerable to Insecure Deserialization in versions 1.0.0 - 1.4.1.
Upgrade the open-dxp/opendxp library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.