Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-wq34-7f4g-953v | Csla affected by Remote Code Execution via WcfProxy (NetDataContractSerializer) |
Wed, 25 Mar 2026 19:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Cslanet
Cslanet csla .net |
|
| CPEs | cpe:2.3:a:cslanet:csla_.net:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Marimer csla .net
|
Cslanet
Cslanet csla .net |
Tue, 17 Mar 2026 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Marimer csla .net
|
|
| CPEs | cpe:2.3:a:marimer:csla_.net:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Marimer csla .net
|
|
| Metrics |
cvssV3_1
|
Tue, 09 Dec 2025 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 09 Dec 2025 10:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Marimer
Marimer csla |
|
| Vendors & Products |
Marimer
Marimer csla |
Tue, 09 Dec 2025 03:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | CSLA .NET is a framework designed for the development of reusable, object-oriented business layers for applications. Versions 5.5.4 and below allow the use of WcfProxy. WcfProxy uses the now-obsolete NetDataContractSerializer (NDCS) and is vulnerable to remote code execution during deserialization. This vulnerability is fixed in version 6.0.0. To workaround this issue, remove the WcfProxy in data portal configurations. | |
| Title | CSLA .NET is vulnerable to Remote Code Execution via WcfProxy | |
| Weaknesses | CWE-502 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2025-12-09T15:15:06.460Z
Reserved: 2025-12-05T15:42:44.716Z
Link: CVE-2025-66631
Updated: 2025-12-09T15:15:02.820Z
Status : Analyzed
Published: 2025-12-09T16:18:22.103
Modified: 2026-03-25T19:09:54.230
Link: CVE-2025-66631
No data.
OpenCVE Enrichment
Updated: 2025-12-09T10:26:30Z
Github GHSA