PT-2022-13409 · Unknown · Singoocms.Utility

Keyang Yin

+2

·

Published

2022-03-17

·

Updated

2022-03-24

·

CVE-2022-0749

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions SinGooCMS.Utility (affected versions not specified)
Description The issue concerns the socket client in the SinGooCMS.Utility package, which lacks appropriate restrictions or type bindings for the BinaryFormatter. This allows user-controllable input to pass in the payload after the socket client has been established.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Deserialization of Untrusted Data

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2022-0749
GHSA-29RV-FQX2-4C9F

Affected Products

Singoocms.Utility