CyberRota Analysis
AI-GeneratedThe GDPR Framework by Data443 versions up to 2.5.0 is vulnerable to unauthenticated PHP Object Injection, allowing attackers to exploit this flaw to execute arbitrary code on the server. This critical vulnerability, rated 9.8 on the CVSS scale, poses a significant risk to any organization utilizing affected versions, particularly those handling sensitive data. Organizations using this framework should prioritize immediate patching or upgrading to mitigate potential exploitation.
CVE
CVE-2026-39797
Severity
CRITICAL
CVSS
9.8
EPSS
N/A
Original NVD Description
Unauthenticated PHP Object Injection in GDPR Framework By Data443 <= 2.5.0 versions.