ZeroHour

CVE-2021-29654

PoC
CVSS 3.1
7.2 high
EPSS
2%p82
Published
()
Modified
Description

AjaxSearchPro before 4.20.8 allows Deserialization of Untrusted Data (in the import database feature of the administration panel), leading to Remote Code execution.

Vendors
stackpath
Products
ajaxsearchpro
Weakness
CWE-502
Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.