Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-6xj5-fx7c-xvcj

Опубликовано: 01 авг. 2025
Источник: github
Github: Не прошло ревью
CVSS4: 8.5

Описание

Kloxo versions 6.1.12 and earlier contain two setuid root binaries—lxsuexec and lxrestart—that allow local privilege escalation from uid 48. The lxsuexec binary performs a uid check and permits execution of arbitrary commands as root if the invoking user matches uid 48. This flaw enables attackers with Apache-level access to escalate privileges to root without authentication.

Kloxo versions 6.1.12 and earlier contain two setuid root binaries—lxsuexec and lxrestart—that allow local privilege escalation from uid 48. The lxsuexec binary performs a uid check and permits execution of arbitrary commands as root if the invoking user matches uid 48. This flaw enables attackers with Apache-level access to escalate privileges to root without authentication.

EPSS

Процентиль: 80%
0.0138
Низкий

8.5 High

CVSS4

Дефекты

CWE-269

Связанные уязвимости

nvd
6 месяцев назад

Kloxo versions 6.1.12 and earlier contain two setuid root binaries—lxsuexec and lxrestart—that allow local privilege escalation from uid 48. The lxsuexec binary performs a uid check and permits execution of arbitrary commands as root if the invoking user matches uid 48. This flaw enables attackers with Apache-level access to escalate privileges to root without authentication.

EPSS

Процентиль: 80%
0.0138
Низкий

8.5 High

CVSS4

Дефекты

CWE-269