CVE-2021-23758

KEV
🔴 Łataj teraz

Deserializacja niezaufanych danych w ajaxpro.2 umożliwia zdalne wykonanie kodu.

CVSS
8.1
EPSS
83.6%
Exploit
weaponized
Vendor
ajaxpro.2_project
Opis źródłowy (NVD)

All versions of package ajaxpro.2 are vulnerable to Deserialization of Untrusted Data due to the possibility of deserialization of arbitrary .NET classes, which can be abused to gain remote code execution.

deserialization exploit rce Brak patcha
Źródła i daty
ŹródłoWartość
NVD – CVSS8.1
CISA KEV (aktywnie wykorzystywane)Tak
FIRST EPSS (prawdopodobieństwo exploita)83.6%
Opublikowano (NVD)2021-12-03 20:15:07 UTC
Ostatnia modyfikacja (NVD)2026-08-27 04:16:38 UTC
Referencje