Company
Date Published
Author
Karim El Ouerghemmi, Thomas Chauchefoin
Word count
1987
Language
English
Hacker News points
None

Summary

The static analysis engine of a software solution detected three critical vulnerabilities in the Melis Platform, an open-source suite with business-oriented features, including an e-commerce component and a CMS. The vulnerabilities exist due to deserialization issues in the Laminas framework, which is used by Melis Platform. These vulnerabilities can be exploited using "popchain" techniques, where attackers create a chain of classes that lead to arbitrary code execution or other severe consequences. The engine's support for popular PHP frameworks and its ability to perform taint analysis make it effective in detecting such vulnerabilities. A patch has been released to fix the issue, and users are urged to upgrade their instances to 5.0.1 and above to benefit from these patches.