Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-j772-g9x7-9q95

Опубликовано: 03 дек. 2025
Источник: github
Github: Не прошло ревью
CVSS3: 6.2

Описание

A local privilege escalation vulnerability exists in the InstallationHelper service included with Plugin Alliance Installation Manager v1.4.0 for macOS. The service accepts unauthenticated XPC connections and executes input via system(), which may allow a local user to execute arbitrary commands with root privileges.

A local privilege escalation vulnerability exists in the InstallationHelper service included with Plugin Alliance Installation Manager v1.4.0 for macOS. The service accepts unauthenticated XPC connections and executes input via system(), which may allow a local user to execute arbitrary commands with root privileges.

EPSS

Процентиль: 4%
0.0002
Низкий

6.2 Medium

CVSS3

Дефекты

CWE-269

Связанные уязвимости

CVSS3: 6.2
nvd
2 месяца назад

A local privilege escalation vulnerability exists in the InstallationHelper service included with Plugin Alliance Installation Manager v1.4.0 for macOS. The service accepts unauthenticated XPC connections and executes input via system(), which may allow a local user to execute arbitrary commands with root privileges.

EPSS

Процентиль: 4%
0.0002
Низкий

6.2 Medium

CVSS3

Дефекты

CWE-269