Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2024-5675

Опубликовано: 06 июн. 2024
Источник: nvd
CVSS3: 10
CVSS3: 9.8
EPSS Низкий

Описание

Untrusted data deserialization vulnerability has been found in Mentor - Employee Portal, affecting version 3.83.35. This vulnerability could allow an attacker to execute arbitrary code, by injecting a malicious payload into the “ViewState” field.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:summar:mentor:3.83.35:*:*:*:*:*:*:*

EPSS

Процентиль: 42%
0.00205
Низкий

10 Critical

CVSS3

9.8 Critical

CVSS3

Дефекты

CWE-502

Связанные уязвимости

CVSS3: 10
github
больше 1 года назад

Untrusted data deserialization vulnerability has been found in Mentor - Employee Portal, affecting version 3.83.35. This vulnerability could allow an attacker to execute arbitrary code, by injecting a malicious payload into the “ViewState” field.

EPSS

Процентиль: 42%
0.00205
Низкий

10 Critical

CVSS3

9.8 Critical

CVSS3

Дефекты

CWE-502