Impact
The vulnerability is a deserialization of untrusted data that permits code injection, enabling an attacker to execute arbitrary code with the privileges of the CSM application. This flaw is identified as CWE‑502 and carries a CVSS score of 9.8, indicating a high‑severity risk to confidentiality, integrity, and availability of all data accessed by the application.
Affected Systems
The affected product is Next4Biz Information Technologies Inc.'s CSM (Customer Service Management). All releases up to 07092026 are vulnerable; no further version granularity is specified.
Risk and Exploitability
The CVSS score of 9.8 reflects a remote code execution vector. The vulnerability is not yet listed in CISA's KEV catalog, but given the lack of vendor response and the nature of the flaw, it represents a high risk. The attack likely requires the ability to supply or influence serialized data that the application deserializes, which could be achieved through exposed APIs or untrusted user input.
OpenCVE Enrichment