What the vulnerability does
01Description
Deserialization of Untrusted Data vulnerability in Hercules Design Hercules Core.This issue affects Hercules Core : from n/a through 6.4.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
What the vulnerability does
Deserialization of Untrusted Data vulnerability in Hercules Design Hercules Core.This issue affects Hercules Core : from n/a through 6.4.
Explanation of Vulnerability in Simple Terms
Hercules Core versions up to 6.4 contain a deserialization vulnerability that allows authenticated attackers to execute arbitrary code on the server. The flaw exists in how the product processes untrusted serialized data without proper validation. An attacker with low-level access can craft malicious input to trigger code execution with full system privileges, affecting confidentiality, integrity, and availability.
What an attacker can do
Run their own code on the server with full system privileges.
Potential impact on your site
Complete compromise of the server: data theft, site defacement, malware installation, and service disruption.
Conditions required to exploit
Attacker must have a low-privilege account or login credentials to access the application.
Key dates
External resources
Related vulnerabilities