Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Nico Viakowski

Researcher fromThinking Objects GmbH
#33457of 53,632
7.8Total CVSS
Vulnerabilities · 1
PT-2023-27411
7.8
2023-10-19
Secudos · Secudos Qiata · CVE-2023-40361
**Name of the Vulnerable Software and Affected Versions** SECUDOS Qiata (DOMOS OS) version 4.13 **Description** The issue is related to insecure permissions for the `previewRm.sh` daily cronjob. An attacker needs access as a low-privileged user to the underlying DOMOS system to exploit this. Every user on the system has write permission for `previewRm.sh`, which is executed by the root user. **Recommendations** For SECUDOS Qiata (DOMOS OS) version 4.13, consider restricting write permissions for the `previewRm.sh` script to prevent low-privileged users from modifying it. As a temporary workaround, consider disabling the execution of the `previewRm.sh` cronjob until a patch is available.