GHSA-74r6-grj9-8rq6
Dashboard / Vulnerabilities / GHSA-74r6-grj9-8rq6
GHSA-74r6-grj9-8rq6
Summary: Duplicate Advisory: Remote Code Execution in AjaxNetProfessional
Details: ## Duplicate Advisory This advisory has been withdrawn because it is a duplicate of GHSA-6r7c-6w96-8pvw. This link is maintained to preserve external references. ## Original Description All versions of package ajaxpro.2 are vulnerable to Deserialization of Untrusted Data due to the possibility of deserialization of arbitrary .NET classes, which can be abused to gain remote code execution.
References: https://github.com/michaelschwarz/Ajax.NET-Professional/security/advisories/GHSA-6r7c-6w96-8pvw, https://nvd.nist.gov/vuln/detail/CVE-2021-23758, https://github.com/michaelschwarz/Ajax.NET-Professional/commit/b0e63be5f0bb20dfce507cb8a1a9568f6e73de57, https://github.com/michaelschwarz/Ajax.NET-Professional, https://snyk.io/vuln/SNYK-DOTNET-AJAXPRO2-1925971, http://packetstormsecurity.com/files/175677/AjaxPro-Deserialization-Remote-Code-Execution.html
Affected packages
Package
Name: AjaxNetProfessional
Purl: pkg:nuget/AjaxNetProfessional
Affected ranges
Type: ECOSYSTEM
Events:
