CVE-2021-36231

Severity CVSS v4.0:
Pending analysis
Type:
CWE-502 Deserialization of Untrusted Dat
Publication date:
31/08/2021
Last modified:
08/09/2021

Description

Deserialization of untrusted data in multiple functions in MIK.starlight 7.9.5.24363 allows authenticated remote attackers to execute operating system commands by crafting serialized objects.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:unit4:mik.starlight:7.9.5.24363:*:*:*:*:*:*:*