THREATINT

We use these services and cookies to improve your user experience. You may opt out if you wish, however, this may limit some features on this site.

Please see our statement on Data Privacy.

Zendesk (Helpdesk and Chat)

Ok

PUBLISHED

CVE-2024-4461

Unquoted path or search item vulnerability in SugarSync

Assigner:INCIBE (0cbda920-cd7f-484a-8e76-bf7f4b7f4516)
Reserved:2024-05-03
Published:2024-05-03
Updated:2024-06-06

Description

Unquoted path or search item vulnerability in SugarSync versions prior to 4.1.3 for Windows. This misconfiguration could allow an unauthorized local user to inject arbitrary code into the unquoted service path, resulting in privilege escalation.



HIGH: 7.8CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Problem types

CWE-428 Unquoted Search Path or Element

Product status

Default status
unaffected

Any version before 4.1.3
affected

Credits

Jorge Manuel Lozano Gómez finder

References

https://www.incibe.es/en/incibe-cert/notices/aviso/unquoted-path-or-search-item-vulnerability-sugarsync

cve.org CVE-2024-4461

nvd.nist.gov CVE-2024-4461

Download JSON

Share this page
https://cve.threatint.com/CVE/CVE-2024-4461