Sceawere
Vulnerability Detail
CVE-2026-62044UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Super Video Player Object Injection
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 7.2
- Creation Date
- 3h ago
- Vendor
- bPlugins
- Product
- Super Video Player
- Attack Type
- Deserialization of Untrusted Data
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
- Attack Complexity
- LOW
Narrative and Response
Description
Deserialization of Untrusted Data vulnerability in bPlugins Super Video Player super-video-player allows Object Injection.This issue affects Super Video Player: from n/a through 1.8.13.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "7.2",
"pubDate": "2026-10-10T17:17:00.803Z",
"pubdate": "2026-10-10T17:17:00.803Z",
"executiveSummary": "The bPlugins Super Video Player plugin is susceptible to an Object Injection vulnerability, categorized under Deserialization of Untrusted Data.\nThis vulnerability impacts all versions of the product from n/a through 1.8.13.\nThe flaw arises when the application deserializes user-supplied input without proper validation or integrity checks.\nSuccessful exploitation allows an unauthenticated or authenticated attacker to inject malicious PHP objects into the application scope.\nThe potential impact of this vulnerability is severe, as it can lead to arbitrary code execution, unauthorized data access, or the modification of application state depending on the presence of gadget chains within the environment.\nThe risk is critical, as it bypasses standard security controls by manipulating the internal object state of the PHP application.\nThere are no specific exploitation requirements listed, but the attacker must be able to reach the vulnerable endpoint where the unsanitized data is processed.\nOrganizations using this plugin are advised to restrict access to administrative interfaces and monitor for unauthorized serialization patterns.",
"technicalDetails": "The vulnerability is rooted in the insecure implementation of deserialization functions within the Super Video Player plugin codebase. In PHP environments, the unserialize() function is often utilized to restore object state from a stored or transmitted string representation. When the application passes untrusted user input directly into this function without prior sanitization, verification, or usage of an allowlist, it creates a critical security weakness.\nThe attack flow begins when an attacker identifies an endpoint or input parameter within the Super Video Player plugin that accepts serialized data. By crafting a malicious serialized string containing a populated class object, the attacker can manipulate the application's runtime state. This process is known as PHP Object Injection.\nUpon deserialization, the PHP engine instantiates the object represented by the malicious payload. If the application contains specific 'gadget chains'—existing classes with 'magic methods' such as __wakeup(), __destruct(), or __toString()—the attacker can trigger these methods upon object destruction or interaction. These magic methods can be leveraged to execute unintended logic, such as file system operations, database queries, or remote command execution.\nThe scope of this vulnerability encompasses all versions up to and including 1.8.13. Because the vulnerability exists at the core logic level of the plugin's data handling mechanisms, it does not necessarily require high-level administrative privileges, assuming the vulnerable entry point is accessible to the attacker's current user level or is exposed publicly.\nThe post-exploitation impact is significantly dependent on the available code base of the environment. Even without an immediate Remote Code Execution (RCE) payload, an attacker can perform Object Injection to facilitate Denial of Service (DoS) by corrupting object states, perform unauthorized authentication bypasses by overwriting security tokens, or conduct arbitrary file deletions if the magic methods interact with the file system. The lack of cryptographic signing on the serialized data prevents the application from verifying that the object state has not been tampered with prior to instantiation. The exploit remains highly effective against standard PHP configurations that do not employ strict object filtering or memory-level isolation for deserialization tasks."
}