CVE-2025-2244

A vulnerability in the sendMailFromRemoteSource method in Emails.php  as used in Bitdefender GravityZone Console unsafely uses php unserialize() on user-supplied input without validation. By crafting a malicious serialized payload, an attacker can trigger PHP object injection, perform a file write, and gain arbitrary command execution on the host system.
Configurations

Configuration 1 (hide)

cpe:2.3:a:bitdefender:gravityzone:*:*:*:*:*:*:*:*

History

30 Jul 2025, 19:04

Type Values Removed Values Added
First Time Bitdefender
Bitdefender gravityzone
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 9.8
CPE cpe:2.3:a:bitdefender:gravityzone:*:*:*:*:*:*:*:*
References () http://bitdefender.com/support/security-advisories/insecure-php-deserialization-issue-in-gravityzone-console-va-12634 - () http://bitdefender.com/support/security-advisories/insecure-php-deserialization-issue-in-gravityzone-console-va-12634 - Vendor Advisory

04 Apr 2025, 10:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-04-04 10:15

Updated : 2025-07-30 19:04


NVD link : CVE-2025-2244

Mitre link : CVE-2025-2244


JSON object : View

Products Affected

bitdefender

  • gravityzone
CWE
CWE-502

Deserialization of Untrusted Data