Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Jorge Manuel Lozano Gómez

#17223of 53,633
15.6Total CVSS
Vulnerabilities · 2
High
2
PT-2024-31196
7.8
2024-05-03
Sugarsync · Sugarsync · CVE-2024-4461
**Name of the Vulnerable Software and Affected Versions** SugarSync versions prior to 4.1.3 **Description** The issue is related to an unquoted path or search item vulnerability. This misconfiguration could allow an unauthorized local user to inject arbitrary code into the unquoted service path, resulting in privilege escalation. **Recommendations** For versions prior to 4.1.3, update to version 4.1.3 or later to resolve the issue. As a temporary workaround, consider restricting access to the service path to minimize the risk of exploitation.
PT-2024-17400
7.8
2024-02-02
Unknown · Hdd Health · CVE-2024-1201
**Name of the Vulnerable Software and Affected Versions** HDD Health versions 4.2.0.112 and earlier **Description** A search path or unquoted item issue could allow a local attacker to store a malicious executable file within the unquoted search path, resulting in privilege escalation. **Recommendations** For versions 4.2.0.112 and earlier, update to a version later than 4.2.0.112 to resolve the issue. As a temporary workaround, consider restricting access to the search path to minimize the risk of exploitation.