Security
Headlines
HeadlinesLatestCVEs

Headline

GHSA-vh38-ghx6-vmvg: Code Injection in Masuit.Tools.Core

All versions of package Masuit.Tools.Core are vulnerable to Arbitrary Code Execution via the ReceiveVarData<T> function in the SocketClient.cs component. The socket client in the package can pass in the payload via the user-controllable input after it has been established, because this socket client transmission does not have the appropriate restrictions or type bindings for the BinaryFormatter.

ghsa
#git

Code Injection in Masuit.Tools.Core

High severity GitHub Reviewed Published May 3, 2022 • Updated May 23, 2022

ghsa: Latest News

GHSA-49cc-xrjf-9qf7: SFTPGo allows administrators to restrict command execution from the EventManager