CVE-2023-45798: Yettiesoft Vestcert
Critical severity, CVSS 9.8. EPSS: 0.6% chance of exploitation in the next 30 days.
In Yettiesoft VestCert versions 2.36 to 2.5.29, a vulnerability exists due to improper validation of third-party modules. This allows malicious actors to load arbitrary third-party modules, leading to remote code execution.
Affected products
- Yettiesoft Vestcert: from 2.3.6, before 2.5.30 (fixed in 2.5.30)
Published 2023-10-30. Last modified 2026-06-17.