In Yettiesoft VestCert versions 2.36 to 2.5.29, a...
Critical severity
Unreviewed
Published
Oct 30, 2023
to the GitHub Advisory Database
•
Updated Nov 8, 2023
Description
Published by the National Vulnerability Database
Oct 30, 2023
Published to the GitHub Advisory Database
Oct 30, 2023
Last updated
Nov 8, 2023
In Yettiesoft VestCert versions 2.36 to 2.5.29, a vulnerability exists due to improper validation of third-party modules. This allows malicious actors to load arbitrary third-party modules, leading to remote code execution.
References