PT-2024-30792 · Eyecix · Eyecix Jobsearch

Ananda Dhakal

·

Published

2024-08-29

·

Updated

2024-09-13

·

CVE-2024-43931

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions eyecix JobSearch versions n/a through 2.5.3
Description The issue is related to Deserialization of Untrusted Data, allowing Object Injection in eyecix JobSearch. This problem enables an attacker to inject malicious objects, potentially leading to unauthorized access or control.
Recommendations For versions n/a through 2.5.3, consider disabling deserialization of untrusted data as a temporary workaround until a patch is available. Restrict access to vulnerable components to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Deserialization of Untrusted Data

Weakness Enumeration

Related Identifiers

CVE-2024-43931

Affected Products

Eyecix Jobsearch