PT-2024-3907 · Unknown · Laborofficefree
CVSS v3.1
5.5
Medium
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions:
LaborOfficeFree version 19.10
Description:
The issue is related to inadequate access control in the backup directory of LaborOfficeFree, allowing any authenticated user to read backup files in the directory '%programfiles(x86)% LaborOfficeFree BackUp'. This could potentially lead to the disclosure of protected information.
Recommendations:
For version 19.10, consider restricting access to the backup directory '%programfiles(x86)% LaborOfficeFree BackUp' to prevent unauthorized users from reading sensitive files. As a temporary workaround, limit the permissions of authenticated users to minimize the risk of exploitation.
Fix
Improper Access Control
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Laborofficefree