PT-2024-32694 · Eyecix · Eyecix Jobsearch

Bonds

·

Published

2024-10-10

·

Updated

2024-11-12

·

CVE-2024-47636

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Eyecix JobSearch versions n/a through 2.5.9
Description The issue is related to Deserialization of Untrusted Data, allowing Object Injection in Eyecix JobSearch. This enables potential remote attacks on affected systems.
Recommendations For Eyecix JobSearch versions n/a through 2.5.9, upgrade to a version higher than 2.5.9 as soon as possible to mitigate the risk of Object Injection due to Deserialization of Untrusted Data vulnerability. As a temporary workaround, consider validating all input data to minimize the risk of exploitation until a patch is available.

Fix

Deserialization of Untrusted Data

Weakness Enumeration

Related Identifiers

CVE-2024-47636

Affected Products

Eyecix Jobsearch