Vulnerabilities > CVE-2021-29654 - Deserialization of Untrusted Data vulnerability in Stackpath Ajaxsearchpro

047910
CVSS 7.2 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
HIGH
Confidentiality impact
HIGH
Integrity impact
HIGH
Availability impact
HIGH
network
low complexity
stackpath
CWE-502

Summary

AjaxSearchPro before 4.20.8 allows Deserialization of Untrusted Data (in the import database feature of the administration panel), leading to Remote Code execution.

Vulnerable Configurations

Part Description Count
Application
Stackpath
1

Common Weakness Enumeration (CWE)