Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-3g4h-66cq-c8vg

Опубликовано: 24 июн. 2024
Источник: github
Github: Не прошло ревью
CVSS3: 7.7

Описание

The application Faronics WINSelect (Standard + Enterprise) saves its configuration in an encrypted file on the file system which "Everyone" has read and write access to, path to file:

C:\ProgramData\WINSelect\WINSelect.wsd

The path for the affected WINSelect Enterprise configuration file is:

C:\ProgramData\Faronics\StorageSpace\WS\WINSelect.wsd

The application Faronics WINSelect (Standard + Enterprise) saves its configuration in an encrypted file on the file system which "Everyone" has read and write access to, path to file:

C:\ProgramData\WINSelect\WINSelect.wsd

The path for the affected WINSelect Enterprise configuration file is:

C:\ProgramData\Faronics\StorageSpace\WS\WINSelect.wsd

EPSS

Процентиль: 13%
0.00043
Низкий

7.7 High

CVSS3

Дефекты

CWE-276

Связанные уязвимости

CVSS3: 7.7
nvd
больше 1 года назад

The application Faronics WINSelect (Standard + Enterprise) saves its configuration in an encrypted file on the file system which "Everyone" has read and write access to, path to file: C:\ProgramData\WINSelect\WINSelect.wsd The path for the affected WINSelect Enterprise configuration file is: C:\ProgramData\Faronics\StorageSpace\WS\WINSelect.wsd

EPSS

Процентиль: 13%
0.00043
Низкий

7.7 High

CVSS3

Дефекты

CWE-276