packetstormsecurity.com
http://packetstormsecurity.com/files/151035/Ajera-Timesheets-9.10.16-Deserialization.html CVE-2018-20221
HIGH
Ajera Timesheets 9.10.16 - Deserialization of Untrusted Data
Record summary
CVE-2018-20221 has a selected CVSS score of 8.8 (high); EIP currently links 1 catalogued exploit.
Description
Secure/SAService.rem in Deltek Ajera Timesheets 9.10.16 and prior are vulnerable to remote code execution via deserialization of untrusted user input from an authenticated user. The executed code will run as the IIS Application Pool that is running the application.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBAjera Timesheets 9.10.16 - Deserialization of Untrusted DataExploitDB exploitby Anthony ColeNot analyzed1 file
References
3nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2018-20221 exploit-db.com
https://www.exploit-db.com/exploits/46086