PT-2021-15549 · Ajaxpro · Ajaxpro
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
ajaxpro.2 versions prior to 21.11.29.1
Description
This issue involves the deserialization of untrusted data, which occurs when an application deserializes data without sufficient verification, allowing an attacker to control the execution flow or state. In this case, the software allows the deserialization of arbitrary .NET classes, which can be abused to achieve remote code execution. This flaw has been reported as actively exploited in real-world incidents.
Recommendations
Update ajaxpro.2 to version 21.11.29.1 or later.
Exploit
Fix
RCE
Deserialization of Untrusted Data
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ajaxpro