CVE-2021-23758

HIGH8.1Pubblicata il 3 dicembre 2021

All versions of package ajaxpro.2 are vulnerable to Deserialization of Untrusted Data due to the possibility of deserialization of arbitrary .NET classes, which can be abused to gain remote code execution.

Preallarme: sfruttamento osservato

  • Sfruttamento osservato dal 20 ago 2026
  • Non ancora nel catalogo ufficiale CISA
  • Primo attacco osservato 1720 giorni dopo la divulgazione

Fonte: VulnCheck KEV · 20 ago 2026

Punteggio CVSS8.1 / 10CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Tipo di debolezza (CWE)CWE-502
Vendorajaxpro.2 project

Prodotti coinvolti

VendorProdottoVersioni
ajaxpro.2 projectajaxpro.2< 21.10.30.1

Articoli correlati

This product uses the NVD API but is not endorsed or certified by the NVD.

Database CVE