PT-2024-35251 · Unknown · Flowcraft Ux Design Studio

Bonds

·

Published

2024-11-16

·

Updated

2024-11-18

·

CVE-2024-52411

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Flowcraft UX Design Studio Advanced Personalization versions from n/a through 1.1.2
Description The issue is related to Deserialization of Untrusted Data, which allows Object Injection. This problem affects the Advanced Personalization component of Flowcraft UX Design Studio.
Recommendations For versions from n/a through 1.1.2, update to a version that fixes the Deserialization of Untrusted Data vulnerability to prevent Object Injection. As a temporary workaround, consider restricting the deserialization of untrusted data until a patch is available.

Fix

Deserialization of Untrusted Data

Weakness Enumeration

Related Identifiers

CVE-2024-52411

Affected Products

Flowcraft Ux Design Studio