OpenCATS v0.9.6 was discovered to contain a remote code execution (RCE) vulnerability via the getDataGridPager's ajax functionality.
The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.
Link | Tags |
---|---|
https://github.com/hansmach1ne/opencats_zero-days/blob/main/RCE_via_deserialisation.md | third party advisory exploit |