PT-2024-3907 · Unknown · Laborofficefree

·

CVE-2024-1343

·

Published

2024-02-19

·

Updated

2024-02-20

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions: LaborOfficeFree version 19.10
Description: The issue is related to inadequate access control in the backup directory of LaborOfficeFree, allowing any authenticated user to read backup files in the directory '%programfiles(x86)% LaborOfficeFree BackUp'. This could potentially lead to the disclosure of protected information.
Recommendations: For version 19.10, consider restricting access to the backup directory '%programfiles(x86)% LaborOfficeFree BackUp' to prevent unauthorized users from reading sensitive files. As a temporary workaround, limit the permissions of authenticated users to minimize the risk of exploitation.

Fix

Improper Access Control

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2024-04317
CVE-2024-1343

Affected Products

Laborofficefree