Описание
Untrusted data deserialization vulnerability has been found in Mentor - Employee Portal, affecting version 3.83.35. This vulnerability could allow an attacker to execute arbitrary code, by injecting a malicious payload into the “ViewState” field.
Уязвимые конфигурации
Конфигурация 1
cpe:2.3:a:summar:mentor:3.83.35:*:*:*:*:*:*:*
EPSS
Процентиль: 42%
0.00205
Низкий
10 Critical
CVSS3
9.8 Critical
CVSS3
Дефекты
CWE-502
Связанные уязвимости
CVSS3: 10
github
больше 1 года назад
Untrusted data deserialization vulnerability has been found in Mentor - Employee Portal, affecting version 3.83.35. This vulnerability could allow an attacker to execute arbitrary code, by injecting a malicious payload into the “ViewState” field.
EPSS
Процентиль: 42%
0.00205
Низкий
10 Critical
CVSS3
9.8 Critical
CVSS3
Дефекты
CWE-502