CVE-2021-23758

HIGH8.1Veröffentlicht am 3. Dezember 2021

All versions of package ajaxpro.2 are vulnerable to Deserialization of Untrusted Data due to the possibility of deserialization of arbitrary .NET classes, which can be abused to gain remote code execution.

Frühwarnung: Ausnutzung beobachtet

  • Ausnutzung beobachtet seit dem 20. Aug. 2026
  • Noch nicht im offiziellen CISA-Katalog
  • Erster Angriff 1720 Tage nach der Veröffentlichung beobachtet

Quelle: VulnCheck KEV · 20. Aug. 2026

CVSS-Score8.1 / 10CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Schwachstellentyp (CWE)CWE-502
Herstellerajaxpro.2 project

Betroffene Produkte

HerstellerProdottoVersioni
ajaxpro.2 projectajaxpro.2< 21.10.30.1

Verwandte Artikel

This product uses the NVD API but is not endorsed or certified by the NVD.

CVE-Datenbank