{"id":25651174,"url":"https://github.com/moften/cve-2024-24926","last_synced_at":"2026-02-17T03:38:54.801Z","repository":{"id":267516675,"uuid":"901496601","full_name":"moften/CVE-2024-24926","owner":"moften","description":"Vulnerabilidad CVE-2024-24926 afecta al tema Brooklyn de WordPress","archived":false,"fork":false,"pushed_at":"2024-12-11T16:39:02.000Z","size":4,"stargazers_count":0,"open_issues_count":1,"forks_count":0,"subscribers_count":1,"default_branch":"main","last_synced_at":"2025-10-13T10:12:42.526Z","etag":null,"topics":[],"latest_commit_sha":null,"homepage":null,"language":null,"has_issues":true,"has_wiki":null,"has_pages":null,"mirror_url":null,"source_name":null,"license":null,"status":null,"scm":"git","pull_requests_enabled":true,"icon_url":"https://github.com/moften.png","metadata":{"files":{"readme":"README.md","changelog":null,"contributing":null,"funding":null,"license":null,"code_of_conduct":null,"threat_model":null,"audit":null,"citation":null,"codeowners":null,"security":null,"support":null,"governance":null,"roadmap":null,"authors":null,"dei":null,"publiccode":null,"codemeta":null,"zenodo":null,"notice":null,"maintainers":null,"copyright":null,"agents":null,"dco":null,"cla":null}},"created_at":"2024-12-10T19:08:03.000Z","updated_at":"2024-12-11T16:39:06.000Z","dependencies_parsed_at":"2024-12-10T20:24:27.148Z","dependency_job_id":"b5540656-6eda-4483-a818-3560094c6a39","html_url":"https://github.com/moften/CVE-2024-24926","commit_stats":null,"previous_names":["moften/cve-2024-24926"],"tags_count":0,"template":false,"template_full_name":null,"purl":"pkg:github/moften/CVE-2024-24926","repository_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/moften%2FCVE-2024-24926","tags_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/moften%2FCVE-2024-24926/tags","releases_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/moften%2FCVE-2024-24926/releases","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/moften%2FCVE-2024-24926/manifests","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/moften","download_url":"https://codeload.github.com/moften/CVE-2024-24926/tar.gz/refs/heads/main","sbom_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/moften%2FCVE-2024-24926/sbom","scorecard":null,"host":{"name":"GitHub","url":"https://github.com","kind":"github","repositories_count":286080680,"owners_count":29532437,"icon_url":"https://github.com/github.png","version":null,"created_at":"2022-05-30T11:31:42.601Z","updated_at":"2026-02-17T03:01:11.216Z","status":"ssl_error","status_checked_at":"2026-02-17T03:00:31.803Z","response_time":100,"last_error":"SSL_connect returned=1 errno=0 peeraddr=140.82.121.5:443 state=error: unexpected eof while reading","robots_txt_status":"success","robots_txt_updated_at":"2025-07-24T06:49:26.215Z","robots_txt_url":"https://github.com/robots.txt","online":false,"can_crawl_api":true,"host_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories","repository_names_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repository_names","owners_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners"}},"keywords":[],"created_at":"2025-02-23T16:19:18.911Z","updated_at":"2026-02-17T03:38:54.783Z","avatar_url":"https://github.com/moften.png","language":null,"funding_links":[],"categories":[],"sub_categories":[],"readme":"# CVE-2024-24926\nVulnerabilidad CVE-2024-24926 afecta al tema Brooklyn de WordPress\n\nDescription: \nLa vulnerabilidad CVE-2024-24926 afecta al tema Brooklyn de WordPress (versiones hasta 4.9.7.6) y está relacionada con la deserialización de datos no confiables (CWE-502). Esto permite que un atacante envíe objetos maliciosos al servidor, potencialmente logrando ejecución remota de código. Según la evaluación de CVSS v3.1, tiene una puntuación de 7.5 (Alta), con un vector de ataque basado en red, alta complejidad, privilegios bajos requeridos, y sin interacción del usuario.\n\nObjeto serializado en PHP\n\n\u003c?php\nclass Malicious {\n    public $cmd = 'system(\"whoami\");';\n}\necho base64_encode(serialize(new Malicious()));\n?\u003e\n\n","project_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fmoften%2Fcve-2024-24926","html_url":"https://awesome.ecosyste.ms/projects/github.com%2Fmoften%2Fcve-2024-24926","lists_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fmoften%2Fcve-2024-24926/lists"}