PT-2023-2027 · Starsoftcomm · Coocare

Happy0717

·

Published

2023-03-03

·

Updated

2025-03-07

·

CVE-2022-45988

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions starsoftcomm CooCare version 5.304
Description The issue is related to insecure privilege management in the CooCare software, allowing local attackers to escalate privileges and execute arbitrary commands via a crafted file upload. This can enable an attacker to gain elevated access and perform unauthorized actions.
Recommendations For starsoftcomm CooCare version 5.304, consider restricting file upload capabilities to prevent exploitation until a patch is available. As a temporary workaround, limit local access to the software to minimize the risk of privilege escalation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Improper Privilege Management

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2023-01739
CVE-2022-45988

Affected Products

Coocare