logo

How Serialized Cookies Led to RCE on a WordPress Website

ID: 61c66c90-aed2-5608-bc4a-b6f0d08d1b3b

STIX ID: report--61c66c90-aed2-5608-bc4a-b6f0d08d1b3b

Feed Name: HackerOne Blog

Threat Score
70/100

Date Published: 2024-11-26

Date Updated: 2026-06-12

...
...

This report documents an insecure deserialization vulnerability in Nextcloud's WordPress custom theme where a cookie (nc_form_fields) was base64-decoded and passed to PHP unserialize(), enabling RCE via gadget chains such as Monolog's FingersCrossedHandler; the issue was responsibly disclosed and patched by replacing unserialize with json_decode.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.