Deserialization of Untrusted Data in Gambio through 4.9.2.0 allows attackers to run arbitrary code via "search" parameter of the Parcelshopfinder/AddAddressBookEntry" function.
The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.
The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.
Link | Tags |
---|---|
https://herolab.usd.de/security-advisories/usd-2023-0046/ | third party advisory exploit |