Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-3v97-26cx-c3v7

Опубликовано: 06 июн. 2025
Источник: github
Github: Не прошло ревью
CVSS4: 9.9
CVSS3: 9.8

Описание

A deserialization of untrusted data vulnerability in the download file function of Soar Cloud HRD Human Resource Management System through version 7.3.2025.0408 allows remote attackers to execute arbitrary system commands via a crafted serialized object.

A deserialization of untrusted data vulnerability in the download file function of Soar Cloud HRD Human Resource Management System through version 7.3.2025.0408 allows remote attackers to execute arbitrary system commands via a crafted serialized object.

EPSS

Процентиль: 60%
0.00391
Низкий

9.9 Critical

CVSS4

9.8 Critical

CVSS3

Дефекты

CWE-502

Связанные уязвимости

CVSS3: 9.8
nvd
8 месяцев назад

A deserialization of untrusted data vulnerability in the download file function of Soar Cloud HRD Human Resource Management System through version 7.3.2025.0408 allows remote attackers to execute arbitrary system commands via a crafted serialized object.

EPSS

Процентиль: 60%
0.00391
Низкий

9.9 Critical

CVSS4

9.8 Critical

CVSS3

Дефекты

CWE-502