Aller au contenu

Fiche vulnérabilité

CVE-2022-0749 : faille critique singoo singoocms.utility (CVSS 9.8)

Description

This affects all versions of package SinGooCMS.Utility. The socket client in the package can pass in the payload via the user-controllable input after it has been established, because this socket client transmission does not have the appropriate restrictions or type bindings for the BinaryFormatter.

En bref

Sévérité
Critique (CVSS 9.8)
Vecteur CVSS
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitation active
Non signalée par la CISA
Publication
17 mars 2022
Dernière mise à jour
17 juin 2026

Produits concernés

  • singoo singoocms.utility

Références

Rechercher une autre vulnérabilité dans la base CVE