Impact
Deserialization of untrusted data in Next4Biz Information Technologies Inc.'s CSM (Customer Service Management) allows code injection, enabling an attacker to execute arbitrary code with application privileges and compromise confidentiality, integrity, and availability. This flaw is identified as CWE‑502 and carries a CVSS score of 9.8.
Affected Systems
The affected product is Next4Biz Information Technologies Inc.'s CSM (Customer Service Management). Versions before 8.0.3 are vulnerable; no further version granularity is specified.
Risk and Exploitability
The CVSS score of 9.8 reflects a remote code execution vector. The vulnerability is not yet listed in CISA's KEV catalog, but given the lack of vendor response and the nature of the flaw, it represents a high risk. The attack likely requires the ability to supply or influence serialized data that the application deserializes, which could be achieved through exposed APIs or untrusted user input. The EPSS score indicates an exploitation probability of less than 1 percent, signifying a low current likelihood of exploitation.
OpenCVE Enrichment