CVE-2022-0749

HIGH

SinGooCMS.Utility - Code Injection

Title source: llm

Description

This affects all versions of package SinGooCMS.Utility. The socket client in the package can pass in the payload via the user-controllable input after it has been established, because this socket client transmission does not have the appropriate restrictions or type bindings for the BinaryFormatter.

Scores

CVSS v3 7.4
EPSS 0.0050
EPSS Percentile 65.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:H

Classification

CWE
CWE-502
Status published

Affected Products (2)

singoo/singoocms.utility
nuget/SinGooCMS.Utility NuGet

Timeline

Published Mar 17, 2022
Tracked Since Feb 18, 2026