CVE-2022-21167

All versions of package masuit.tools.core are vulnerable to Arbitrary Code Execution via the ReceiveVarData<T> function in the SocketClient.cs component. The socket client in the package can pass in the payload via the user-controllable input after it has been established, because this socket client transmission does not have the appropriate restrictions or type bindings for the BinaryFormatter.
Configurations

Configuration 1 (hide)

cpe:2.3:a:ldqk:masuit.tools:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2022-05-01 16:15

Updated : 2024-11-21 06:44


NVD link : CVE-2022-21167

Mitre link : CVE-2022-21167

CVE.ORG link : CVE-2022-21167


JSON object : View

Products Affected

ldqk

  • masuit.tools