
Saloon patches unsafe unserialize enabling PHP object injection
Saloon fixed unsafe `unserialize()` in `AccessTokenAuthenticator` OAuth token restore, where attacker-controlled serialized state can trigger PHP object injection and potential RCE in versions `< 4.0.0`.
NewsPHPInsecure Deserialization
2 minYesterday

