ZeroHour

CVE-2021-39273

PoC ×2
CVSS 3.1
8.8 high
EPSS
3%p85
Published
()
Modified
Description

In XeroSecurity Sn1per 9.0 (free version), insecure permissions (0777) are set upon application execution, allowing an unprivileged user to modify the application, modules, and configuration files. This leads to arbitrary code execution with root privileges.

Vendors
xerosecurity
Products
sn1per
Weakness
CWE-276
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.