Описание
A vulnerability was found in anji-plus AJ-Report up to 1.4.1. It has been declared as critical. Affected by this vulnerability is the function getValueFromJs of the component Javascript Handler. The manipulation leads to deserialization. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-266263.
Ссылки
- Exploit
- Broken Link
- Permissions RequiredVDB Entry
- Third Party AdvisoryVDB Entry
- Exploit
- Broken Link
- Permissions RequiredVDB Entry
- Third Party AdvisoryVDB Entry
Уязвимые конфигурации
Конфигурация 1Версия до 1.4.1 (включая)
cpe:2.3:a:anji-plus:aj-report:*:*:*:*:*:*:*:*
EPSS
Процентиль: 28%
0.00099
Низкий
6.3 Medium
CVSS3
9.8 Critical
CVSS3
6.5 Medium
CVSS2
Дефекты
CWE-502
EPSS
Процентиль: 28%
0.00099
Низкий
6.3 Medium
CVSS3
9.8 Critical
CVSS3
6.5 Medium
CVSS2
Дефекты
CWE-502