PT-2024-13947 · Fit2Cloud · Fit2Cloud Cloud Explorer Lite

Published

2024-01-05

·

Updated

2024-01-11

·

CVE-2023-50612

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions fit2cloud Cloud Explorer Lite version 1.4.1
Description The issue allows local attackers to escalate privileges and obtain sensitive information via the cloud accounts parameter. This is due to an Insecure Permissions vulnerability.
Recommendations For fit2cloud Cloud Explorer Lite version 1.4.1, consider restricting access to the cloud accounts parameter to minimize the risk of exploitation until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Incorrect Default Permissions

Weakness Enumeration

Related Identifiers

CVE-2023-50612

Affected Products

Fit2Cloud Cloud Explorer Lite