Allegra renderFieldMatch Deserialization of Unstrusted Data Remote Code Execution Vulnerability
CVE-2023-51641
6.3MEDIUM
What is CVE-2023-51641?
A deserialization vulnerability exists within the renderFieldMatch method of Allegra by TrackPlus, which allows remote attackers to execute arbitrary code in affected installations. While authentication is required for exploitation, the product's registration mechanism can be exploited to create a user with sufficient privileges. The flaw arises from inadequate validation of user-supplied data, leading to the deserialization of untrusted data and execution of code in the context of LOCAL SERVICE, posing a significant security risk.
Affected Version(s)
Allegra 7.5.0 build 29
References
EPSS Score
6% chance of being exploited in the next 30 days.
CVSS V3.1
Score:
6.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
CVSS V3.0
Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
