Описание
GFI MailEssentials prior to version 21.8 is vulnerable to a .NET deserialization issue. A remote and authenticated attacker can execute arbitrary code by sending crafted serialized .NET when joining to a Multi-Server setup.
Ссылки
- Exploit
- Release Notes
Уязвимые конфигурации
Конфигурация 1Версия до 21.8 (исключая)
cpe:2.3:a:gfi:mailessentials:*:*:*:*:*:*:*:*
EPSS
Процентиль: 63%
0.00439
Низкий
8.8 High
CVSS3
Дефекты
CWE-502
CWE-502
Связанные уязвимости
CVSS3: 8.8
github
9 месяцев назад
GFI MailEssentials prior to version 21.8 is vulnerable to a .NET deserialization issue. A remote and authenticated attacker can execute arbitrary code by sending crafted serialized .NET when joining to a Multi-Server setup.
EPSS
Процентиль: 63%
0.00439
Низкий
8.8 High
CVSS3
Дефекты
CWE-502
CWE-502