PT-2024-32694 · Eyecix · Eyecix Jobsearch

·

CVE-2024-47636

·

Published

2024-10-10

·

Updated

2024-11-12

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Eyecix JobSearch versions n/a through 2.5.9
Description The issue is related to Deserialization of Untrusted Data, allowing Object Injection in Eyecix JobSearch. This enables potential remote attacks on affected systems.
Recommendations For Eyecix JobSearch versions n/a through 2.5.9, upgrade to a version higher than 2.5.9 as soon as possible to mitigate the risk of Object Injection due to Deserialization of Untrusted Data vulnerability. As a temporary workaround, consider validating all input data to minimize the risk of exploitation until a patch is available.

Fix

Deserialization of Untrusted Data

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-47636

Affected Products

Eyecix Jobsearch