An issue was discovered in Kaseya Unitrends Backup Appliance before 10.5.5. The wguest account could execute commands by injecting into PostgreSQL trigger functions. This allowed privilege escalation from the wguest user to the postgres user.
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: mitre

Published: 2021-12-06T00:00:00

Updated: 2022-11-23T00:00:00

Reserved: 2021-10-26T00:00:00


Link: CVE-2021-43038

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2021-12-06T04:15:07.340

Modified: 2022-11-28T21:39:48.667


Link: CVE-2021-43038

JSON object: View

cve-icon Redhat Information

No data.

CWE