CVE Database
/

CVE-2025-2244

Back to search

CVE-2025-2244

Published: Apr 4, 2025

Modified: Apr 4, 2025

PUBLISHED

Description

A vulnerability in the sendMailFromRemoteSource method in Emails.php  as used in Bitdefender GravityZone Console unsafely uses php unserialize() on user-supplied input without validation. By crafting a malicious serialized payload, an attacker can trigger PHP object injection, perform a file write, and gain arbitrary command execution on the host system.

VendorProductVersions

Bitdefender

GravityZone Console

affected
0 - < 6.41.2-1

Weaknesses (CWE)

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now
CVE-2025-2244 - Security Vulnerability | QwikSec