PT-2019-7914 · Bittorrent+1 · Qbittorrent+1

CVE-2017-12778

·

Publicado

2017-09-11

·

Atualizado

2024-08-05

CVSS v3.1

7.1

Alta

VetorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions qBittorrent version 3.3.15
Description The issue concerns the UI Lock feature, which can be bypassed by tampering with the config file. An attacker can gain unauthorized access to qBittorrent functions by modifying the locked attribute within the Locking stanza in the config file located at C:Users<username>RoamingqBittorrent. However, it is noted that this behavior is intended.
Recommendations For qBittorrent version 3.3.15, consider using alternative security measures, as the UI Lock feature can be bypassed by modifying the config file. Avoid relying solely on the UI Lock feature for security.

Exploit

Correção

Improper Authentication

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALT-PU-2017-2185
CVE-2017-12778

Produtos afetados

Alt Linux
Qbittorrent