Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-q9wc-hhm5-fjq7

Опубликовано: 29 мая 2026
Источник: github
Github: Не прошло ревью
CVSS4: 5.1
CVSS3: 5

Описание

Improper handling of symbolic links in the installer of My Image Garden for macOS Version 3.6.8 or earlier may allow a local attacker with login privileges to exploit a specially crafted symbolic link during installation to modify permissions of files for which they would not normally have authorization.

Improper handling of symbolic links in the installer of My Image Garden for macOS Version 3.6.8 or earlier may allow a local attacker with login privileges to exploit a specially crafted symbolic link during installation to modify permissions of files for which they would not normally have authorization.

EPSS

Процентиль: 2%
0.00123
Низкий

5.1 Medium

CVSS4

5 Medium

CVSS3

Дефекты

CWE-59

Связанные уязвимости

CVSS3: 5
nvd
2 месяца назад

Improper handling of symbolic links in the installer of My Image Garden for macOS Version 3.6.8 or earlier may allow a local attacker with login privileges to exploit a specially crafted symbolic link during installation to modify permissions of files for which they would not normally have authorization.

EPSS

Процентиль: 2%
0.00123
Низкий

5.1 Medium

CVSS4

5 Medium

CVSS3

Дефекты

CWE-59