Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-qm9m-fp5f-xg9x

Опубликовано: 13 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 8.8

Описание

It was discovered that an issue in the session logic in Unitrends Backup (UB) before 10.0.0 allowed using the LOGDIR environment variable during a web session to elevate an existing low-privilege user to root privileges. A remote attacker with existing low-privilege credentials could then execute arbitrary commands with root privileges.

It was discovered that an issue in the session logic in Unitrends Backup (UB) before 10.0.0 allowed using the LOGDIR environment variable during a web session to elevate an existing low-privilege user to root privileges. A remote attacker with existing low-privilege credentials could then execute arbitrary commands with root privileges.

EPSS

Процентиль: 94%
0.13453
Средний

8.8 High

CVSS3

Связанные уязвимости

CVSS3: 8.8
nvd
больше 8 лет назад

It was discovered that an issue in the session logic in Unitrends Backup (UB) before 10.0.0 allowed using the LOGDIR environment variable during a web session to elevate an existing low-privilege user to root privileges. A remote attacker with existing low-privilege credentials could then execute arbitrary commands with root privileges.

EPSS

Процентиль: 94%
0.13453
Средний

8.8 High

CVSS3