CVE-2022-39298 is a critical deserialization vulnerability affecting MelisFront, the engine powering websites on the Melis Platform, specifically versions of melisplatform/melis-front prior to 5.0.1. This unauthenticated flaw allows attackers to execute arbitrary PHP code on the system by deserializing malicious user-controlled data. With a CVSS score of 9.8 (CRITICAL), it presents a severe risk due to its network-based attack vector, low complexity, and complete compromise of confidentiality, integrity, and availability. While no active exploitation, public exploit code, or significant community discussion has been observed, immediate upgrade to version 5.0.1 or higher is strongly recommended to mitigate this high-impact vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 5.0.1CPE matchmatch criteria | cpe:2.3:a:melistechnology:meliscms:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.