PT-2022-8288 · Ajenti · Ajenti
Jeremy Brown
·
Published
2022-06-09
·
Updated
2022-06-15
·
CVE-2019-25066
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
ajenti version 2.1.31
Description
A critical issue has been found in the API component, leading to privilege escalation through remote attack. The exploit has been disclosed publicly.
Recommendations
For version 2.1.31, upgrade to version 2.1.32 to address this issue.
Exploit
Fix
Improper Privilege Management
OS Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Ajenti