b2evolution CMS versions 6.7.8 through 7.2.5 contain an incomplete fix for CVE-2016-8901 where the serialized-array object check in param_check_serialized_array() fails to reject payloads with negative integer array keys. Unauthenticated attackers can submit crafted serialized PHP objects via POST requests to htsrv/call_plugin.php that bypass validation and reach unserialize(), instantiating arbitrary PHP objects with attacker-chosen properties that may enable code execution if suitable POP gadget chains exist.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Thu, 17 Sep 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | b2evolution CMS versions 6.7.8 through 7.2.5 contain an incomplete fix for CVE-2016-8901 where the serialized-array object check in param_check_serialized_array() fails to reject payloads with negative integer array keys. Unauthenticated attackers can submit crafted serialized PHP objects via POST requests to htsrv/call_plugin.php that bypass validation and reach unserialize(), instantiating arbitrary PHP objects with attacker-chosen properties that may enable code execution if suitable POP gadget chains exist. | |
| Title | b2evolution CMS 6.7.8 through 7.2.5 Object Injection via Negative Integer Array Key | |
| First Time appeared |
B2evolution
B2evolution b2evolution Cms |
|
| Weaknesses | CWE-502 | |
| CPEs | cpe:2.3:a:b2evolution:b2evolution_cms:*:*:*:*:*:*:*:* | |
| Vendors & Products |
B2evolution
B2evolution b2evolution Cms |
|
| References |
|
|
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-09-17T15:16:50.748Z
Reserved: 2026-08-19T20:34:00.154Z
Link: CVE-2026-76834
No data.
No data.
No data.
OpenCVE Enrichment
No data.
Weaknesses