Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Mon, 21 Sep 2026 17:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Deserialization of Untrusted Data in CuteNews Allowing Arbitrary Request Variable Injection | |
| Weaknesses | CWE-502 |
Mon, 21 Sep 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Deserialization of Untrusted Data of the __post_data parameter in cn_parse_url() in CuteNews v.2.1.2 allows a remote attacker to inject arbitrary values into internal request variables (including __referer) via a crafted base64-encoded serialized PHP payload submitted as a POST parameter. | |
| References |
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2026-09-21T15:18:25.751Z
Reserved: 2026-04-06T00:00:00.000Z
Link: CVE-2026-36471
No data.
Status : Received
Published: 2026-09-21T16:17:08.090
Modified: 2026-09-21T16:17:08.090
Link: CVE-2026-36471
No data.
OpenCVE Enrichment
Updated: 2026-09-21T17:30:18Z