9
CVE-2021-36231
- EPSS 1.14%
- Veröffentlicht 31.08.2021 18:15:07
- Zuletzt bearbeitet 21.11.2024 06:13:21
- Quelle cve@mitre.org
- CVE-Watchlists
- Unerledigt
Deserialization of untrusted data in multiple functions in MIK.starlight 7.9.5.24363 allows authenticated remote attackers to execute operating system commands by crafting serialized objects.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Unit4 ≫ Mik.Starlight Version7.9.5.24363
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 1.14% | 0.778 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 8.8 | 2.8 | 5.9 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
|
| nvd@nist.gov | 9 | 8 | 10 |
AV:N/AC:L/Au:S/C:C/I:C/A:C
|
CWE-502 Deserialization of Untrusted Data
The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.