10
CVSSv2

CVE-2021-39274

Published: 19/08/2021 Updated: 30/08/2021
CVSS v2 Base Score: 10 | Impact Score: 10 | Exploitability Score: 10
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 891
Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

In XeroSecurity Sn1per 9.0 (free version), insecure directory permissions (0777) are set during installation, allowing an unprivileged user to modify the main application and the application configuration file. This results in arbitrary code execution with root privileges.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

xerosecurity sn1per 9.0

Github Repositories

Two security issues identified in Sn1per v9.0 free version by XeroSecurity

CVE-2021-39273 In XeroSecurity Sn1per 90 (free version), insecure permissions (0777) are set upon application execution, allowing an unprivileged user to modify the application, modules, and configuration files This leads to arbitrary code execution with root privileges CVE-2021-39274 In XeroSecurity Sn1per 90 (free version), insecure directory permissions (0777) are set du

Two security issues identified in Sn1per v9.0 free version by XeroSecurity

CVE-2021-39273 In XeroSecurity Sn1per 90 (free version), insecure permissions (0777) are set upon application execution, allowing an unprivileged user to modify the application, modules, and configuration files This leads to arbitrary code execution with root privileges CVE-2021-39274 In XeroSecurity Sn1per 90 (free version), insecure directory permissions (0777) are set du