CVE-2021-29654
HIGHStackpath Ajaxsearchpro < 4.20.8 - Insecure Deserialization
Title source: ruleDescription
AjaxSearchPro before 4.20.8 allows Deserialization of Untrusted Data (in the import database feature of the administration panel), leading to Remote Code execution.
Scores
CVSS v3
7.2
EPSS
0.0189
EPSS Percentile
83.0%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Classification
CWE
CWE-502
Status
published
Affected Products (1)
stackpath/ajaxsearchpro
< 4.20.8
Timeline
Published
Apr 14, 2021
Tracked Since
Feb 18, 2026