ZDI-CAN-21907: ZDI-25-128: NI G Web Development GWEBPROJECT File Parsing Deserialization of Untrusted Data Remote Code Execution Vulnerability
This vulnerability allows remote attackers to execute arbitrary code on affected installations of NI G Web Development. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2024-12742.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-CAN-21907?
The severity of ZDI-CAN-21907 is significant as it allows remote code execution through user interaction.
How do I fix ZDI-CAN-21907?
To fix ZDI-CAN-21907, update to the latest version of NI G Web Development that addresses this vulnerability.
Who is affected by ZDI-CAN-21907?
Any installation of NI G Web Development is potentially affected by ZDI-CAN-21907.
What are the requirements to exploit ZDI-CAN-21907?
Exploitation of ZDI-CAN-21907 requires user interaction, such as visiting a malicious page or opening a malicious file.
What type of vulnerability is ZDI-CAN-21907 categorized as?
ZDI-CAN-21907 is categorized as a remote code execution vulnerability.