Zend Framework/Laminas untrusted deserialization RCE exploit

  • The Proof of Concept (PoC) exploits posted by the researcher show how CVE-2021-3007 can be exploited to gain remote code execution (RCE) on vulnerable PHP applications built with Zend Framework aka Laminas.