CVE-2022-21167

All versions of package masuit.tools.core are vulnerable to Arbitrary Code Execution via the ReceiveVarData<T> function in the SocketClient.cs component. The socket client in the package can pass in the payload via the user-controllable input after it has been established, because this socket client transmission does not have the appropriate restrictions or type bindings for the BinaryFormatter.
Configurations

Configuration 1 (hide)

cpe:2.3:a:idqk:masuit.tools:*:*:*:*:*:*:*:*

Information

Published : 2022-05-01 16:15

Updated : 2022-05-11 14:01


NVD link : CVE-2022-21167

Mitre link : CVE-2022-21167


JSON object : View

Products Affected

idqk

  • masuit.tools