7.8
CVSSv3

CVE-2023-40361

Published: 20/10/2023 Updated: 26/10/2023
CVSS v3 Base Score: 7.8 | Impact Score: 5.9 | Exploitability Score: 1.8
VMScore: 0

Vulnerability Summary

SECUDOS Qiata (DOMOS OS) 4.13 has Insecure Permissions for the previewRm.sh daily cronjob. To exploit this, an attacker needs access as a low-privileged user to the underlying DOMOS system. Every user on the system has write permission for previewRm.sh, which is executed by the root user.

Vulnerable Product Search on Vulmon Subscribe to Product

secudos qiata 4.13

Github Repositories

Security Vulnerability - SECUDOS Qiata

CVE-2023-40361 This vulnerability was discovered and disclosed by myself This repository will hold the advisory This repository is only for educational purposes Links Blog Post Thinking Objects: tocom/news/advisory-secudos-qiata-cve-2023-40361 Blog Post SECUDOS GmbH: wwwsecudosde/news/penetrationstest-von-thinking-objects-sicherheit-auf-hoechstem-niveau M