An issue was discovered in Gentics CMS before 5.43.1. By uploading a malicious ZIP file, an attacker is able to deserialize arbitrary data and hence can potentially achieve Java code execution.
                
            References
                    | Link | Resource | 
|---|---|
| https://sec-consult.com/vulnerability-lab/advisory/multiple-vulnerabilies-in-gentics-cms/ | Third Party Advisory | 
Configurations
                    Information
                Published : 2022-07-17 16:15
Updated : 2022-07-21 15:24
NVD link : CVE-2022-30981
Mitre link : CVE-2022-30981
JSON object : View
CWE
                
                    
                        
                        CWE-502
                        
            Deserialization of Untrusted Data
Products Affected
                gentics
- gentics_cms


