In Yettiesoft VestCert versions 2.36 to 2.5.29, a...
        
  Critical severity
        
          Unreviewed
      
        Published
          Oct 30, 2023 
          to the GitHub Advisory Database
          •
          Updated Nov 8, 2023 
      
  
Description
        Published by the National Vulnerability Database
      Oct 30, 2023 
    
  
        Published to the GitHub Advisory Database
      Oct 30, 2023 
    
  
        Last updated
      Nov 8, 2023 
    
  
In Yettiesoft VestCert versions 2.36 to 2.5.29, a vulnerability exists due to improper validation of third-party modules. This allows malicious actors to load arbitrary third-party modules, leading to remote code execution.
References