PT-2026-21185 · Themerex · Extreme Store

CVE-2025-69404

·

Publicado

2026-02-20

·

Atualizado

2026-02-21

CVSS v3.1

9.8

Crítica

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions ThemeREX Extreme Store versions through 1.5.7
Description A flaw exists in ThemeREX Extreme Store that allows for object injection due to deserialization of untrusted data. This condition can be exploited by an attacker to potentially compromise the system.
Recommendations Update ThemeREX Extreme Store to a version newer than 1.5.7.

Correção

Deserialization of Untrusted Data

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2025-69404

Produtos afetados

Extreme Store