THREATOPS
THREAT OPSThreat News › [NVD] CVE-2021-23758 (HIGH 8.1) — All versions of package ajaxpro.2 are vulnerable to Deserialization of Untrusted Data due to the possibility of deserialization of arbitrary .NET classes, which can be abused to gain remote code execution.

[NVD] CVE-2021-23758 (HIGH 8.1) — All versions of package ajaxpro.2 are vulnerable to Deserialization of Untrusted Data due to the possibility of deserialization of arbitrary .NET classes, which can be abused to gain remote code execution.

lownvdPublished 2021-12-03

CVE-2021-23758 CVSS: 8.1 HIGH Published: 2021-12-03T20:15:07.557

All versions of package ajaxpro.2 are vulnerable to Deserialization of Untrusted Data due to the possibility of deserialization of arbitrary .NET classes, which can be abused to gain remote code execution.

Indicators of compromise

Original source: https://nvd.nist.gov/vuln/detail/CVE-2021-23758