PT-2024-30414 · Crew Hrm · Crew Hrm

Catfather

·

Published

2024-08-19

·

Updated

2024-08-23

·

CVE-2024-43252

CVSS v3.1

9.0

Critical

VectorAV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Crew HRM versions n/a through 1.1.1
Description The Deserialization of Untrusted Data issue in Crew HRM allows Object Injection. This problem affects Crew HRM, enabling potential exploitation.
Recommendations For Crew HRM versions n/a through 1.1.1, update to a version later than 1.1.1 to resolve the issue. At the moment, there is no information about additional mitigation measures for this specific vulnerability.

Fix

Deserialization of Untrusted Data

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-43252

Affected Products

Crew Hrm