Object Injection Vulnerability in PlainInventory by Plainware
CVE-2024-56291

8.1HIGH

Key Information:

Vendor
WordPress
Vendor
CVE Published:
7 January 2025

Summary

The PlainInventory product from Plainware is affected by a vulnerability that allows for object injection due to deserialization of untrusted data. This flaw can enable malicious actors to execute potentially harmful code within the application, thereby compromising its integrity and security. The vulnerability impacts versions from release n/a through 3.1.6, making it crucial for users to update their systems promptly to mitigate any associated risks.

Affected Version(s)

PlainInventory <= 3.1.6

References

CVSS V3.1

Score:
8.1
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

LVT-tholv2k (Patchstack Alliance)
.