ZDI-25-128: NI G Web Development GWEBPROJECT File Parsing Deserialization of Untrusted Data Remote Code Execution Vulnerability
This vulnerability allows remote attackers to execute arbitrary code on affected installations of NI G Web Development. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2024-12742.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-25-128?
ZDI-25-128 has a high severity rating due to its potential for remote code execution.
How do I fix ZDI-25-128?
To fix ZDI-25-128, ensure that you update NI G Web Development to the latest patched version.
Who is affected by ZDI-25-128?
Users of NI G Web Development are at risk from the ZDI-25-128 vulnerability.
What type of attack is ZDI-25-128 associated with?
ZDI-25-128 is associated with remote code execution attacks requiring user interaction.
What are the potential consequences of exploiting ZDI-25-128?
Exploiting ZDI-25-128 could allow attackers to execute arbitrary code on the affected system.