PT-2022-8288 · Ajenti · Ajenti

Jeremy Brown

·

Published

2022-06-09

·

Updated

2022-06-15

·

CVE-2019-25066

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions ajenti version 2.1.31
Description A critical issue has been found in the API component, leading to privilege escalation through remote attack. The exploit has been disclosed publicly.
Recommendations For version 2.1.31, upgrade to version 2.1.32 to address this issue.

Exploit

Fix

Improper Privilege Management

OS Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2019-25066

Affected Products

Ajenti