hacktimepro/vulnerabilities

hacktimepro/vulnerabilities

Releases0

CVE History

CVEPublishedCVSS v3CVSS v2
6.2 MEDIUM

An Insecure Permission vulnerability in pgcodekeeper 10.12.0 allows a local attacker to obtain sensitive information via the plaintext storage of passwords and usernames.

8.2 HIGH

The Utils.deserialize function in pgCodeKeeper 10.12.0 processes serialized data from untrusted sources. If an attacker provides a specially crafted .ser file, deserialization may result in unintended code execution or other malicious behavior on the target system.