CNNVD-202507-707 Information

CNNVD ID

CNNVD-202507-707

CVE-2025-6811

  • CNNVD Published: 2025-07-07

Description (Chinese)

Mescius ActiveReports.NET是日本Mescius公司的一款.NET报表工具。 Mescius ActiveReports.NET存在代码问题漏洞,该漏洞源于TypeResolutionService类未正确验证用户提供数据,可能导致反序列化攻击和远程代码执行。

Description (English)

Mescius Active Reports.NET is a NET reporting tool for Mescius, Japan. Mescius Active Reports.NET has a code gap that stems from the incorrect validation of data provided by users in the TypeResolation Service category, which may result in a back-serialization attack and remote code execution.

Hazard Level

Low

Vulnerability Type

代码问题

Affected Vendor

Meshery

Published

2025-07-07

Last Modified

2026-02-24

References

https://www.zerodayinitiative.com/advisories/ZDI-25-449/

Patch

https://developer.mescius.com/activereportsnet/download

Share on: