CVE-2021-23758
Summary
| CVE | CVE-2021-23758 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2021-12-03 20:15:00 UTC |
| Updated | 2023-11-14 03:15:00 UTC |
| Description | All versions of package ajaxpro.2 are vulnerable to Deserialization of Untrusted Data due to the possibility of deserialization of arbitrary .NET classes, which can be abused to gain remote code execution. |
Risk And Classification
Problem Types: CWE-502
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Ajaxpro.2 Project | Ajaxpro.2 | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Deserialization of Untrusted Data in ajaxpro.2 | Snyk | CONFIRM | snyk.io | |
| added allowed customized types · michaelschwarz/Ajax.NET-Professional@b0e63be · GitHub | CONFIRM | github.com | |
| packetstormsecurity.com/files/175677/AjaxPro-Deserialization-Remote-Code-Execution.html | packetstormsecurity.com | ||
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
Discovery Credit
LEGACY: Hans-Martin Münch (MOGWAI LABS)
There are currently no legacy QID mappings associated with this CVE.