CVE-2024-11839

Severity CVSS v4.0:
HIGH
Type:
CWE-502 Deserialization of Untrusted Dat
Publication date:
13/12/2024
Last modified:
01/10/2025

Description

Deserialization of Untrusted Data vulnerability in PlexTrac (Runbooks modules) which allows Object Injection and arbitrary file writes.This issue affects PlexTrac: from 1.61.3 before 2.8.1.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:plextrac:plextrac:*:*:*:*:*:*:*:* 1.61.3 (including) 2.8.1 (excluding)