SP LMS (com_splms) R Deserializes - Question | JoomShaper

Celebrate JoomShaper's Sweet 16 with Flat 35% OFF!

SP LMS (com_splms) R Deserializes

T

Torsten.S

General 4 hours ago

Are u aware of the follownig ?

https://github.com/advisories/GHSA-gf8c-xmwj-whrh

SP LMS (com_splms) < 4.1.4 by JoomShaper deserializes user-controlled cookie data without validation, enabling an unauthenticated remote attacker to execute arbitrary code on the server.

0
1 Answers
Atick Eashrak Shuvo
Atick Eashrak Shuvo
Accepted Answer
Support Agent 3 hours ago #226683

Thank you for bringing this to our attention.

Yes, we are aware of this security advisory. The reported vulnerability has already been addressed and fixed in the latest version of SP LMS.

To ensure your website remains secure, we strongly recommend updating SP LMS to the latest available version as soon as possible. If you are already running the latest version, no further action is required regarding this specific issue.

Please let us know if you need any assistance with the update process.

Thank you for your vigilance and cooperation.

0