mirror of
https://github.com/0xMarcio/cve.git
synced 2026-05-27 02:02:23 +02:00
757 B
757 B
CVE-2021-27335
Description
KollectApps before 4.8.16c is affected by insecure Java deserialization, leading to Remote Code Execution via a ysoserial.payloads.CommonsCollections parameter.
POC
Reference
- https://hacked0x90.net/index.php/2021/02/15/kollectapp-insecure-java-deserialization/
- https://hacked0x90.net/index.php/2021/02/15/kollectapp-insecure-java-deserialization/
Github
No PoCs found on GitHub currently.