PT-2021-15549 · Ajaxpro · Ajaxpro

·

CVE-2021-23758

·

Published

2021-12-03

·

Updated

2026-09-02

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions ajaxpro.2 versions prior to 21.11.29.1
Description This issue involves the deserialization of untrusted data, which occurs when an application deserializes data without sufficient verification, allowing an attacker to control the execution flow or state. In this case, the software allows the deserialization of arbitrary .NET classes, which can be abused to achieve remote code execution. This flaw has been reported as actively exploited in real-world incidents.
Recommendations Update ajaxpro.2 to version 21.11.29.1 or later.

Exploit

Fix

RCE

Deserialization of Untrusted Data

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-23758
GHSA-6R7C-6W96-8PVW
GHSA-74R6-GRJ9-8RQ6
SNYK-DOTNET-AJAXPRO2-1925971

Affected Products

Ajaxpro