Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-w966-799g-fp7v

Опубликовано: 06 июн. 2024
Источник: github
Github: Не прошло ревью
CVSS3: 10

Описание

Untrusted data deserialization vulnerability has been found in Mentor - Employee Portal, affecting version 3.83.35. This vulnerability could allow an attacker to execute arbitrary code, by injecting a malicious payload into the “ViewState” field.

Untrusted data deserialization vulnerability has been found in Mentor - Employee Portal, affecting version 3.83.35. This vulnerability could allow an attacker to execute arbitrary code, by injecting a malicious payload into the “ViewState” field.

EPSS

Процентиль: 42%
0.00205
Низкий

10 Critical

CVSS3

Дефекты

CWE-502

Связанные уязвимости

CVSS3: 10
nvd
больше 1 года назад

Untrusted data deserialization vulnerability has been found in Mentor - Employee Portal, affecting version 3.83.35. This vulnerability could allow an attacker to execute arbitrary code, by injecting a malicious payload into the “ViewState” field.

EPSS

Процентиль: 42%
0.00205
Низкий

10 Critical

CVSS3

Дефекты

CWE-502