High severity8.1NVD Advisory· Published Dec 3, 2021· Updated Jun 17, 2026
CVE-2021-23758
CVE-2021-23758
Description
All versions of package ajaxpro.2 are vulnerable to Deserialization of Untrusted Data due to the possibility of deserialization of arbitrary .NET classes, which can be abused to gain remote code execution.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
AjaxNetProfessionalNuGet | < 21.11.29.1 | 21.11.29.1 |
Affected products
2- ajaxpro.2/ajaxpro.2description
Patches
Vulnerability mechanics
References
7- github.com/michaelschwarz/Ajax.NET-Professional/commit/b0e63be5f0bb20dfce507cb8a1a9568f6e73de57nvdPatchThird Party AdvisoryWEB
- github.com/advisories/GHSA-6r7c-6w96-8pvwghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2021-23758ghsaADVISORY
- snyk.io/vuln/SNYK-DOTNET-AJAXPRO2-1925971nvdThird Party Advisory
- packetstormsecurity.com/files/175677/AjaxPro-Deserialization-Remote-Code-Execution.htmlnvdWEB
- github.com/michaelschwarz/Ajax.NET-Professional/security/advisories/GHSA-6r7c-6w96-8pvwghsaWEB
- security.snyk.io/vuln/SNYK-DOTNET-AJAXPRO2-1925971ghsaWEB
News mentions
0No linked articles in our index yet.