Sceawere

Vulnerability Detail

CVE-2026-62044UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Super Video Player Object Injection

Vulnerability Metadata

Severity
High
Score / CVSS
7.2
Creation Date
3h ago
Vendor
bPlugins
Product
Super Video Player
Attack Type
Deserialization of Untrusted Data
Vector String
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Attack Complexity
LOW

Narrative and Response

Description

Deserialization of Untrusted Data vulnerability in bPlugins Super Video Player super-video-player allows Object Injection.This issue affects Super Video Player: from n/a through 1.8.13.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "7.2",
  "pubDate": "2026-10-10T17:17:00.803Z",
  "pubdate": "2026-10-10T17:17:00.803Z",
  "executiveSummary": "The bPlugins Super Video Player plugin is susceptible to an Object Injection vulnerability, categorized under Deserialization of Untrusted Data.\nThis vulnerability impacts all versions of the product from n/a through 1.8.13.\nThe flaw arises when the application deserializes user-supplied input without proper validation or integrity checks.\nSuccessful exploitation allows an unauthenticated or authenticated attacker to inject malicious PHP objects into the application scope.\nThe potential impact of this vulnerability is severe, as it can lead to arbitrary code execution, unauthorized data access, or the modification of application state depending on the presence of gadget chains within the environment.\nThe risk is critical, as it bypasses standard security controls by manipulating the internal object state of the PHP application.\nThere are no specific exploitation requirements listed, but the attacker must be able to reach the vulnerable endpoint where the unsanitized data is processed.\nOrganizations using this plugin are advised to restrict access to administrative interfaces and monitor for unauthorized serialization patterns.",
  "technicalDetails": "The vulnerability is rooted in the insecure implementation of deserialization functions within the Super Video Player plugin codebase. In PHP environments, the unserialize() function is often utilized to restore object state from a stored or transmitted string representation. When the application passes untrusted user input directly into this function without prior sanitization, verification, or usage of an allowlist, it creates a critical security weakness.\nThe attack flow begins when an attacker identifies an endpoint or input parameter within the Super Video Player plugin that accepts serialized data. By crafting a malicious serialized string containing a populated class object, the attacker can manipulate the application's runtime state. This process is known as PHP Object Injection.\nUpon deserialization, the PHP engine instantiates the object represented by the malicious payload. If the application contains specific 'gadget chains'—existing classes with 'magic methods' such as __wakeup(), __destruct(), or __toString()—the attacker can trigger these methods upon object destruction or interaction. These magic methods can be leveraged to execute unintended logic, such as file system operations, database queries, or remote command execution.\nThe scope of this vulnerability encompasses all versions up to and including 1.8.13. Because the vulnerability exists at the core logic level of the plugin's data handling mechanisms, it does not necessarily require high-level administrative privileges, assuming the vulnerable entry point is accessible to the attacker's current user level or is exposed publicly.\nThe post-exploitation impact is significantly dependent on the available code base of the environment. Even without an immediate Remote Code Execution (RCE) payload, an attacker can perform Object Injection to facilitate Denial of Service (DoS) by corrupting object states, perform unauthorized authentication bypasses by overwriting security tokens, or conduct arbitrary file deletions if the magic methods interact with the file system. The lack of cryptographic signing on the serialized data prevents the application from verifying that the object state has not been tampered with prior to instantiation. The exploit remains highly effective against standard PHP configurations that do not employ strict object filtering or memory-level isolation for deserialization tasks."
}
CVE-2026-62044: Super Video Player Object Injection (HIGH Severity, CVSS: 7.2) | Sceawere