CVE-2021-23758
Duplicate Advisory: Remote Code Execution in AjaxNetProfessional
9.8
CRITICAL
CVSS 3.1
EPSS 88.8%
Description
## Duplicate Advisory This advisory has been withdrawn because it is a duplicate of GHSA-6r7c-6w96-8pvw. This link is maintained to preserve external references. ## Original Description All versions of package ajaxpro.2 are vulnerable to Deserialization of Untrusted Data due to the possibility of deserialization of arbitrary .NET classes, which can be abused to gain remote code execution.
How to fix CVE-2021-23758
To remediate CVE-2021-23758, upgrade the affected package to a fixed version below.
- —upgrade to 21.11.29.1 or later
Is CVE-2021-23758 being exploited?
Likely — EPSS is 88.8%, placing CVE-2021-23758 in the top tier of vulnerabilities by exploitation probability. Prioritise patching.
Affected packages (1)
- from 0, < 21.11.29.1
CVSS scores
| Source | Version | Severity | Vector |
|---|---|---|---|
| osv | CVSS 3.1 | CRITICAL9.8 | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |