ChestnutCMS Remote Deserialization Exploit in API Endpoint up to Version 15.1
A critical vulnerability exists in ChestnutCMS versions up to 15.1 within the /dev-api/groovy/exec API Endpoint. This security issue involves a deserialization vulnerability that can be triggered remotely. The vulnerability impacts unknown code in the system and allows an attacker to manipulate data. The exploit details have been publicly disclosed, which means potential attackers could potentially use this vulnerability to compromise the system.
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
* chestnutcms |