PT-2023-2027 · Starsoftcomm · Coocare

Happy0717

·

Publicado

2023-03-03

·

Atualizado

2025-03-07

·

CVE-2022-45988

CVSS v3.1

7.8

Alta

VetorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions starsoftcomm CooCare version 5.304
Description The issue is related to insecure privilege management in the CooCare software, allowing local attackers to escalate privileges and execute arbitrary commands via a crafted file upload. This can enable an attacker to gain elevated access and perform unauthorized actions.
Recommendations For starsoftcomm CooCare version 5.304, consider restricting file upload capabilities to prevent exploitation until a patch is available. As a temporary workaround, limit local access to the software to minimize the risk of privilege escalation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Improper Privilege Management

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2023-01739
CVE-2022-45988

Produtos afetados

Coocare