Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-536p-4pcj-5mr9

Опубликовано: 02 сент. 2021
Источник: github
Github: Прошло ревью
CVSS3: 8.8

Описание

raspap-webgui in RaspAP 2.6.6 allows attackers to execute commands as root because of the insecure sudoers permissions.

raspap-webgui in RaspAP 2.6.6 allows attackers to execute commands as root because of the insecure sudoers permissions. The www-data account can execute /etc/raspap/hostapd/enablelog.sh as root with no password; however, the www-data account can also overwrite /etc/raspap/hostapd/enablelog.sh with any executable content.

Пакеты

Наименование

billz/raspap-webgui

composer
Затронутые версииВерсия исправления

<= 2.6.6

Отсутствует

EPSS

Процентиль: 72%
0.00728
Низкий

8.8 High

CVSS3

Дефекты

CWE-276
CWE-732

Связанные уязвимости

CVSS3: 8.8
nvd
больше 4 лет назад

raspap-webgui in RaspAP 2.6.6 allows attackers to execute commands as root because of the insecure sudoers permissions. The www-data account can execute /etc/raspap/hostapd/enablelog.sh as root with no password; however, the www-data account can also overwrite /etc/raspap/hostapd/enablelog.sh with any executable content.

EPSS

Процентиль: 72%
0.00728
Низкий

8.8 High

CVSS3

Дефекты

CWE-276
CWE-732