CVE-2024-5675: Summar Mentor
Critical severity, CVSS 9.8. EPSS: 0.6% chance of exploitation in the next 30 days.
Untrusted data deserialization vulnerability has been found in Mentor - Employee Portal, affecting version 3.83.35. This vulnerability could allow an attacker to execute arbitrary code, by injecting a malicious payload into the “ViewState” field.
Affected products
- Summar Mentor: version 3.83.35 only
Published 2024-06-06. Last modified 2026-06-17.