Description
Zend/zend_exceptions.c in PHP before 5.4.44, 5.5.x before 5.5.28, and 5.6.x before 5.6.12 does not validate certain Exception objects, which allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) or trigger unintended method execution via crafted serialized data.
Remediation
References
Related Vulnerabilities
WordPress Plugin Ultimate Addons for Beaver Builder Security Bypass (1.24.0)
MyBB URL Redirection to Untrusted Site ('Open Redirect') Vulnerability (CVE-2019-20225)
WordPress Plugin WordPress Related Posts Cross-Site Request Forgery (2.6.1)
Chamilo Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2023-39061)