Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-29rv-fqx2-4c9f

Опубликовано: 18 мар. 2022
Источник: github
Github: Прошло ревью
CVSS3: 9.8

Описание

Deserialization of Untrusted Data in SinGooCMS.Utility

This affects all versions of package SinGooCMS.Utility. The socket client in the package can pass in the payload via the user-controllable input after it has been established, because this socket client transmission does not have the appropriate restrictions or type bindings for the BinaryFormatter.

Пакеты

Наименование

SinGooCMS.Utility

nuget
Затронутые версииВерсия исправления

<= 1.6.2

Отсутствует

EPSS

Процентиль: 64%
0.00474
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-502

Связанные уязвимости

CVSS3: 7.4
nvd
больше 3 лет назад

This affects all versions of package SinGooCMS.Utility. The socket client in the package can pass in the payload via the user-controllable input after it has been established, because this socket client transmission does not have the appropriate restrictions or type bindings for the BinaryFormatter.

EPSS

Процентиль: 64%
0.00474
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-502