CNNVD-202507-707 Information
Jul 07, 2025
cve
CNNVD ID
CNNVD-202507-707
Related CVE
- CNNVD Published: 2025-07-07
Description (Chinese)
Mescius ActiveReports.NET是日本Mescius公司的一款.NET报表工具。 Mescius ActiveReports.NET存在代码问题漏洞,该漏洞源于TypeResolutionService类未正确验证用户提供数据,可能导致反序列化攻击和远程代码执行。
Description (English)
Mescius Active Reports.NET is a NET reporting tool for Mescius, Japan. Mescius Active Reports.NET has a code gap that stems from the incorrect validation of data provided by users in the TypeResolation Service category, which may result in a back-serialization attack and remote code execution.
Hazard Level
Low
Vulnerability Type
代码问题
Affected Vendor
Meshery
Published
2025-07-07
Last Modified
2026-02-24
References
https://www.zerodayinitiative.com/advisories/ZDI-25-449/
Patch
https://developer.mescius.com/activereportsnet/download
Share on: