Middleware/SessionCookie.php in Slim before 2.6.0 allows remote attackers to conduct PHP object injection attacks and execute arbitrary PHP code via crafted session data.
No PoCs from references.
- https://github.com/ARPSyndicate/cvemon
- https://github.com/flouciel/Deserialize
- https://github.com/tthseus/Deserialize