Loading
Archive_Tar through 1.4.10 allows an unserialization attack because phar: is blocked but PHAR: is not blocked.
Use CWE-502, Php vendor hub and Archive Tar product page to widen CVE-2020-28948 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2020-28949, CVE-2020-36193 and CVE-2021-32610 for nearby disclosures in the same product family.