CVE-2025-2244

A vulnerability in the sendMailFromRemoteSource method in Emails.php  as used in Bitdefender GravityZone Console unsafely uses php unserialize() on user-supplied input without validation. By crafting a malicious serialized payload, an attacker can trigger PHP object injection, perform a file write, and gain arbitrary command execution on the host system.
Configurations

Configuration 1 (hide)

cpe:2.3:a:bitdefender:gravityzone:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2025-04-04 10:15

Updated : 2025-07-30 19:04


NVD link : CVE-2025-2244

Mitre link : CVE-2025-2244

CVE.ORG link : CVE-2025-2244


JSON object : View

Products Affected

bitdefender

  • gravityzone
CWE
CWE-502

Deserialization of Untrusted Data