In XeroSecurity Sn1per 9.0 (free version), insecure permissions (0777) are set upon application execution, allowing an unprivileged user to modify the application, modules, and configuration files. This leads to arbitrary code execution with root privileges.
References
Link Resource
https://github.com/1N3/Sn1per/issues/358 Exploit Third Party Advisory
https://github.com/1N3/Sn1per/releases Release Notes Third Party Advisory
https://github.com/nikip72/CVE-2021-39273-CVE-2021-39274 Exploit Third Party Advisory
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: mitre

Published: 2021-08-19T11:59:39

Updated: 2021-08-19T12:05:22

Reserved: 2021-08-18T00:00:00


Link: CVE-2021-39273

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2021-08-19T12:15:09.347

Modified: 2021-08-26T02:02:59.037


Link: CVE-2021-39273

JSON object: View

cve-icon Redhat Information

No data.

CWE