Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:23306
HistoryApr 10, 2020 - 12:22 a.m.

Privilege Escalation

2020-04-1000:22:25
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
14

0.028 Low

EPSS

Percentile

90.8%

mysql is vulnerable to privilege escalation. A flaw was found in a way MySQL handled symbolic links when database tables were created with explicit β€œDATA” and β€œINDEX DIRECTORY” options. An authenticated user could create a table that would overwrite tables in other databases, causing destruction of data or allowing the user to elevate privileges.

References