Deserialization of untrusted data vulnerability in XooNIps 3.49 and earlier allows remote attackers to execute arbitrary code via unspecified vectors.
The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.
Link | Tags |
---|---|
https://xoonips.osdn.jp/modules/news/index.php?page=article&storyid=13 | release notes vendor advisory |
https://jvn.jp/en/vu/JVNVU92053563/index.html | third party advisory |