CVE-2024-49688
CVSS 3.1 Score 9.8 of 10 (high)
Details
Published Jan 21, 2025
CWE ID 502
Summary
CVE-2024-49688 is a deserialization vulnerability affecting NotFound ARPrice versions 4.0.3 and below. An attacker can exploit this issue by providing untrusted data for deserialization, leading to Object Injection. This weakness could allow an attacker to execute arbitrary code or gain unauthorized access to sensitive information. Organizations using NotFound ARPrice are advised to update to a patched version as soon as possible to mitigate this risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.