Deserialization of Untrusted Data in Kleor Contact Manager by Kleor
CVE-2025-68853
8.8HIGH
What is CVE-2025-68853?
A deserialization vulnerability exists in Kleor Contact Manager, which allows for object injection through untrusted data. This security flaw can be exploited by attackers to gain unauthorized access or execute arbitrary code. Affected versions include all prior to 9.1.1, making it critical for users of the Contact Manager to apply necessary updates to safeguard their systems.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Contact Manager <= n/a
References
CVSS V3.1
Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Skalucy | Patchstack Bug Bounty Program