Vulnerability CVE-2024-4461


Published: 2024-05-03

Description:
Unquoted path or search item vulnerability in SugarSync versions prior to 4.1.3 for Windows. This misconfiguration could allow an unauthorized local user to inject arbitrary code into the unquoted service path, resulting in privilege escalation.

Type:

CWE-428

(Unquoted Search Path or Element)

 References:
https://www.incibe.es/en/incibe-cert/notices/aviso/unquoted-path-or-search-item-vulnerability-sugarsync

Copyright 2024, cxsecurity.com

 

Back to Top