Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-2m67-46qp-5j9w

Опубликовано: 15 дек. 2021
Источник: github
Github: Не прошло ревью

Описание

An issue was discovered in Listary through 6. When Listary is configured as admin, Listary will not ask for permissions again if a user tries to access files on the system from Listary itself (it will bypass UAC protection; there is no privilege validation of the current user that runs via Listary).

An issue was discovered in Listary through 6. When Listary is configured as admin, Listary will not ask for permissions again if a user tries to access files on the system from Listary itself (it will bypass UAC protection; there is no privilege validation of the current user that runs via Listary).

EPSS

Процентиль: 47%
0.00242
Низкий

Дефекты

CWE-862

Связанные уязвимости

CVSS3: 7.5
nvd
около 4 лет назад

An issue was discovered in Listary through 6. When Listary is configured as admin, Listary will not ask for permissions again if a user tries to access files on the system from Listary itself (it will bypass UAC protection; there is no privilege validation of the current user that runs via Listary).

EPSS

Процентиль: 47%
0.00242
Низкий

Дефекты

CWE-862