PixelYourSite - Insecure deserialization
Severity pending
Summary
Full name
PixelYourSite- Your smart PIXEL (TAG) and API Manager 10.1.1.1 - Insecure deserialization
Code name
State
Public
Release date
28 feb 2025
Affected product
PixelYourSite- Your smart PIXEL (TAG) and API Manager
Affected version(s)
Version 10.1.1.1
Vulnerability name
Insecure deserialization
Vulnerability type
Remotely exploitable
No
CVSS v4.0 vector string
CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N/E:U
Exploit available
No
CVE ID(s)
Description
PixelYourSite- Your smart PIXEL (TAG) and API Manager 10.1.1.1 was found to be vulnerable. Unvalidated user input is used directly in an unserialize function in myapp/modules/facebook/facebook-server-a sync-task.php.
Vulnerability
Skims by Fluid Attacks discovered a Insecure deserialization in PixelYourSite- Your smart PIXEL (TAG) and API Manager 10.1.1.1. The following is the output of the tool:
Skims output
Our security policy
We have reserved the ID CVE-2025-0769 to refer to this issue from now on.
System Information
Version: PixelYourSite- Your smart PIXEL (TAG) and API Manager 10.1.1.1
Mitigation
The vendor released the following versions with the patch: PixelYourSite Free: 10.1.1.2 and PixelYourSite Pro: 11.2.2.3
Timeline
IA generativa
3 ene 2025
Vendor Confirmed Vuln.
27 feb 2025
Vulnerability patched
28 feb 2025
Vendor contacted
27 feb 2025
Vendor replied
27 feb 2025
Public disclosure
28 feb 2025