Lucene search

K
prionPRIOn knowledge basePRION:CVE-2018-1079
HistoryApr 12, 2018 - 5:29 p.m.

Privilege escalation

2018-04-1217:29:00
PRIOn knowledge base
www.prio-n.com
7

6.7 Medium

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

29.7%

pcs before version 0.9.164 and 0.10 is vulnerable to a privilege escalation via authorized user malicious REST call. The REST interface of the pcsd service did not properly sanitize the file name from the /remote/put_file query. If the /etc/booth directory exists, an authenticated attacker with write permissions could create or overwrite arbitrary files with arbitrary data outside of the /etc/booth directory, in the context of the pcsd process.

6.7 Medium

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

29.7%