Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:5919
HistoryMar 15, 2018 - 4:48 a.m.

Insecure Permissions

2018-03-1504:48:02
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
5

0.001 Low

EPSS

Percentile

21.4%

ajenti.plugin.plugins has insecure permissions when downloading plugins. An attacker can download and install any plugin to the server if they know how the request is made. There is no check to ensure that it is an admin downloading the plugin. Attackers could exploit this vulnerability to install malicious plugins.

CPENameOperatorVersion
ajenti.plugin.pluginsle0.47

0.001 Low

EPSS

Percentile

21.4%

Related for VERACODE:5919