← back
CVE-2021-23758high

Deserialization of Untrusted Data

58Vexday Risk Score

Patch soon. It has a working public exploit.

ssvc Attendcvss 8.1epss 89%
from disclosure to weapon0 days
Published on NVDDec 3
metasploitDec 3
exploitation probability
89%top 1% of all CVEs
observed exploitation
nono source reports it
All versions of package ajaxpro.2 are vulnerable to Deserialization of Untrusted Data due to the possibility of deserialization of arbitrary .NET classes, which can be abused to gain remote code execution.
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected products
n/a · AjaxPro.2