Sceawere

Vulnerability Detail

CVE-2026-94683UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

DesignSetGo PHP Object Injection Vulnerability

Vulnerability Metadata

Severity
High
Score / CVSS
8.8
Creation Date
3h ago
Vendor
Justin Nealey
Product
DesignSetGo
Attack Type
CWE-502 Deserialization of Untrusted Data
Vector String
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Attack Complexity
LOW

Narrative and Response

Description

Contributor PHP Object Injection in DesignSetGo <= 2.8.0 versions.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "8.8",
  "pubDate": "2026-09-30T13:17:27.940Z",
  "pubdate": "2026-09-30T13:17:27.940Z",
  "executiveSummary": "DesignSetGo versions up to and including 2.8.0 are susceptible to a PHP Object Injection vulnerability.\nThis security flaw allows an authenticated attacker to inject malicious serialized objects into the application, potentially leading to Remote Code Execution (RCE), arbitrary file deletion, or sensitive data disclosure.\nThe vulnerability arises from improper validation of user-supplied data during the deserialization process.\nThe risk implication is critical, as it bypasses standard application logic by manipulating the application's internal state through object reconstruction.\nExploitation requires authenticated access, but once triggered, the attacker can leverage existing 'POP chains' (Property Oriented Programming) within the application's codebase to execute arbitrary commands or manipulate system operations with the privileges of the web server user.\nOrganizations using the affected software are at high risk of total system compromise if an attacker with contributor-level access or higher targets the application.",
  "technicalDetails": "The vulnerability is rooted in the unsafe use of the PHP unserialize() function on untrusted user input within the DesignSetGo plugin architecture.\nIn PHP, the unserialize() function is inherently dangerous when processing user-provided strings. When an application accepts serialized data and processes it without rigorous validation, an attacker can supply a specially crafted string that represents a different class or object structure than what the application expects.\nThe attack flow begins when an attacker identifies a user-controllable input vector that is passed into a vulnerable deserialization function. By crafting a serialized payload, the attacker can instantiate arbitrary classes that are currently loaded within the PHP environment, even if those classes were not intended to be initialized by the current execution path.\nBy manipulating the properties of these instantiated objects, an attacker can influence the behavior of the application's magic methods, such as __destruct(), __wakeup(), or __toString().\nThese magic methods, when triggered during object destruction or garbage collection, allow the attacker to execute secondary code paths, often referred to as POP chains. These chains utilize existing code segments (gadgets) already present in the application or its bundled libraries to achieve desired malicious outcomes, such as writing files to the filesystem, executing system commands via backticks or shell_exec(), or altering database records.\nThe vulnerability specifically affects DesignSetGo versions 2.8.0 and earlier. The primary exposure stems from the lack of input sanitization or the use of secure alternatives like JSON-based storage for user configuration or session data.\nBecause the payload is processed server-side, the attacker does not need to bypass client-side protections. The impact is significant, as it grants the attacker the ability to execute arbitrary PHP code, leading to a full compromise of the application's integrity, availability, and confidentiality.\nFurthermore, if the underlying web server is misconfigured or lacks proper sandbox restrictions, the attacker may escalate from the application layer to the host operating system, effectively gaining persistent control over the server environment."
}
CVE-2026-94683: DesignSetGo PHP Object Injection Vulnerability (HIGH Severity, CVSS: 8.8) | Sceawere