Vulnerability CVE-2024-5675


Published: 2024-06-06

Description:
Untrusted data deserialization vulnerability has been found in Mentor - Employee Portal, affecting version 3.83.35. This vulnerability could allow an attacker to execute arbitrary code, by injecting a malicious payload into the ??ViewState? field.

Type:

CWE-502

(Deserialization of Untrusted Data)

 References:
https://www.incibe.es/en/incibe-cert/notices/aviso/unreliable-data-deserialization-vulnerability-mentor

Copyright 2026, cxsecurity.com

 

Back to Top