Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2020-29312


An issue found in Zend Framework v.3.1.3 and before allow a remote attacker to execute arbitrary code via the unserialize function. Note: This has been disputed by third parties as incomplete and incorrect. The framework does not have a version that surpasses 2.x.x and was deprecated in early 2020.


Published

2023-04-04T15:15:08.457

Last Modified

2025-02-18T17:15:11.653

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 9.8 (CRITICAL)

Weaknesses
  • Type: Primary
    CWE-502

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application zend zend_framework ≤ 3.1.3 Yes

References