PT-2024-31196 · Sugarsync · Sugarsync

Jorge Manuel Lozano Gómez

·

Published

2024-05-03

·

Updated

2024-05-03

·

CVE-2024-4461

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions SugarSync versions prior to 4.1.3
Description The issue is related to an unquoted path or search item vulnerability. This misconfiguration could allow an unauthorized local user to inject arbitrary code into the unquoted service path, resulting in privilege escalation.
Recommendations For versions prior to 4.1.3, update to version 4.1.3 or later to resolve the issue. As a temporary workaround, consider restricting access to the service path to minimize the risk of exploitation.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-4461

Affected Products

Sugarsync