9.8
CVSSv3

CVE-2021-23758

Published: 03/12/2021 Updated: 14/11/2023
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

All versions of package ajaxpro.2 are vulnerable to Deserialization of Untrusted Data due to the possibility of deserialization of arbitrary .NET classes, which can be abused to gain remote code execution.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

ajaxpro.2 project ajaxpro.2

Github Repositories

CVE-2021-23758-POC this repo has been created for training on the vulnerability in the ajaxpro disclosed with the ID number CVE-2021-23758 POC POST /ajaxpro/CVE_2021_23758_POCdemo,CVE_2021_23758ashx HTTP/2 Host: localhost:44375 Content-Length: 567 Sec-Ch-Ua: " Not A;Brand";v="99", "Chromium";v="96" X-Ajaxpro-Method: TestAjax Content-T