PT-2023-24173 · Unknown · Aviator Template Engine+1
Dreamfly
·
Published
2023-06-18
·
Updated
2024-05-17
·
CVE-2023-3308
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
whaleal IceFrog version 1.1.8
Description
A problematic vulnerability has been found in the Aviator Template Engine component, leading to deserialization of untrusted data. The manipulation with this issue may be used since the exploit has been disclosed to the public. The application deserializes untrusted data without sufficiently verifying that the resulting data will be valid.
Recommendations
For whaleal IceFrog version 1.1.8, consider restricting the use of the Aviator Template Engine component until a patch is available to prevent deserialization of untrusted data. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Deserialization of Untrusted Data
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Aviator Template Engine
Whaleal Icefrog