CRITICAL

CVE-2021-23758

Ajaxpro.2_project Ajaxpro.2 2021-12-03 CVSS v3.1
CVSS
9.8
KEV

Description

All versions of package ajaxpro.2 are vulnerable to Deserialization of Untrusted Data due to the possibility of deserialization of arbitrary .NET classes, which can be abused to gain remote code execution.

Weakness (CWE)

CWE-502 Deserialization of Untrusted Data

EPSS Score

82.58%
Probability of exploitation in next 30 days
99.7th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE