CVE-2022-30981

Severity CVSS v4.0:
Pending analysis
Type:
CWE-502 Deserialization of Untrusted Dat
Publication date:
17/07/2022
Last modified:
21/07/2022

Description

An issue was discovered in Gentics CMS before 5.43.1. By uploading a malicious ZIP file, an attacker is able to deserialize arbitrary data and hence can potentially achieve Java code execution.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:gentics:gentics_cms:*:*:*:*:*:*:*:* 5.43.1 (excluding)