Phying News
Curated security research, vulnerabilities, advisories and tools for practitioners.

How Serialized Cookies Led to RCE on a WordPress Website

Summary

A bug bounty write-up details an RCE in Nextcloud's WordPress site caused by insecure PHP deserialization in a custom theme, and explains how to identify, assess, and remediate such flaws.
Published
Collected

original ↗

Related coverage

back