Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-8f2r-wvm7-v573

Опубликовано: 29 апр. 2022
Источник: github
Github: Не прошло ревью

Описание

The documentation for CuteNews 1.3.6 and possibly other versions specifies that files under cutenews/data must be manually given world-writable permissions, which allows local users to insert false news, delete news, and possibly gain privileges or have other unknown impact.

The documentation for CuteNews 1.3.6 and possibly other versions specifies that files under cutenews/data must be manually given world-writable permissions, which allows local users to insert false news, delete news, and possibly gain privileges or have other unknown impact.

EPSS

Процентиль: 16%
0.00051
Низкий

Связанные уязвимости

nvd
около 21 года назад

The documentation for CuteNews 1.3.6 and possibly other versions specifies that files under cutenews/data must be manually given world-writable permissions, which allows local users to insert false news, delete news, and possibly gain privileges or have other unknown impact.

EPSS

Процентиль: 16%
0.00051
Низкий