8.8
CVSSv3

CVE-2021-43397

Published: 11/11/2021 Updated: 12/07/2022
CVSS v2 Base Score: 9 | Impact Score: 10 | Exploitability Score: 8
CVSS v3 Base Score: 8.8 | Impact Score: 5.9 | Exploitability Score: 2.8
VMScore: 801
Vector: AV:N/AC:L/Au:S/C:C/I:C/A:C

Vulnerability Summary

LiquidFiles prior to 3.6.3 allows remote malicious users to elevate their privileges from Admin (or User Admin) to Sysadmin.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

liquidfiles liquidfiles

Exploits

LiquidFiles version 3513 suffers from a privilege escalation vulnerability The LiquidFiles API allows a User Admin to access keys for System Administrators ...

Mailing Lists

<!--X-Body-Begin--> <!--X-User-Header--> Full Disclosure mailing list archives <!--X-User-Header-End--> <!--X-TopPNI--> By Date By Thread </form> <!--X-TopPNI-End--> <!--X-MsgBody--> <!--X-Subject-Header-Begin--> Re: Responsible Full disclosure for LiquidFiles 3513 <!--X-Subject-Header-End--> <!--X-Head-of-Message--> From: Ri ...
<!--X-Body-Begin--> <!--X-User-Header--> Full Disclosure mailing list archives <!--X-User-Header-End--> <!--X-TopPNI--> By Date By Thread </form> <!--X-TopPNI-End--> <!--X-MsgBody--> <!--X-Subject-Header-Begin--> Responsible Full disclosure for LiquidFiles 3513 <!--X-Subject-Header-End--> <!--X-Head-of-Message--> From: Riccar ...