Sunnet eHRD e-mail delivery task schedule’s serialization...
High severity
Unreviewed
Published
Dec 2, 2021
to the GitHub Advisory Database
•
Updated Feb 1, 2023
Description
Published by the National Vulnerability Database
Dec 1, 2021
Published to the GitHub Advisory Database
Dec 2, 2021
Last updated
Feb 1, 2023
Sunnet eHRD e-mail delivery task schedule’s serialization function has inadequate input object validation and restriction, which allows a post-authenticated remote attacker with database access privilege, to execute arbitrary code and control the system or interrupt services.
References