CVE-2020-26867

Severity CVSS v4.0:
Pending analysis
Type:
CWE-502 Deserialization of Untrusted Dat
Publication date:
12/10/2020
Last modified:
19/10/2022

Description

ARC Informatique PcVue prior to version 12.0.17 is vulnerable due to the deserialization of untrusted data, which may allow an attacker to remotely execute arbitrary code on the web and mobile back-end server.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:pcvuesolutions:pcvue:*:*:*:*:*:*:*:* 8.10 (including) 12.0.17 (excluding)