CVE-2024-12687

Severity CVSS v4.0:
HIGH
Type:
CWE-502 Deserialization of Untrusted Dat
Publication date:
16/12/2024
Last modified:
10/10/2025

Description

Deserialization of Untrusted Data vulnerability in PlexTrac (Runbooks modules) which allows Object Injection and arbitrary file writes.<br /> <br /> This issue affects PlexTrac: from 1.61.3 before 2.8.1.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:plextrac:plextrac:*:*:*:*:*:*:*:* 1.61.3 (including) 2.8.1 (excluding)