### [CVE-2022-40238](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-40238) ![](https://img.shields.io/static/v1?label=Product&message=VINCE%20-%20The%20Vulnerability%20Information%20and%20Coordination%20Environment&color=blue) ![](https://img.shields.io/static/v1?label=Version&message=%3D%201.48.0%20&color=brighgreen) ![](https://img.shields.io/static/v1?label=Vulnerability&message=CWE-502%3A%20Deserialization%20of%20Untrusted%20Data&color=brighgreen) ### Description A Remote Code Injection vulnerability exists in CERT software prior to version 1.50.5. An authenticated attacker can inject arbitrary pickle object as part of a user's profile. This can lead to code execution on the server when the user's profile is accessed. ### POC #### Reference No PoCs from references. #### Github - https://github.com/battleofthebots/system-gateway