PT-2020-12879 · Ovoice · Ovoicemanager
Published
2020-11-19
·
Updated
2020-12-04
·
CVE-2020-11831
CVSS v2.0
10
Critical
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
OvoiceManager version V2.0.1
Description
The issue allows OvoiceManager to write vulnerability reports for arbitrary files due to its system permission.
Recommendations
For OvoiceManager version V2.0.1, consider restricting the system permission to prevent arbitrary file writes until a patch is available.
Fix
Incorrect Permission
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ovoicemanager