PineApp Mail-SeCure 3.70 and earlier on 5099SK and...
High severity
Unreviewed
Published
May 17, 2022
to the GitHub Advisory Database
•
Updated Jan 28, 2023
Description
Published by the National Vulnerability Database
Nov 20, 2013
Published to the GitHub Advisory Database
May 17, 2022
Last updated
Jan 28, 2023
PineApp Mail-SeCure 3.70 and earlier on 5099SK and earlier platforms has a sudoers file that does not properly restrict user specifications, which allows local users to gain privileges via a sudo command that leverages access to the qmailq account.
References