An improper input validation vulnerability in Helpu solution could allow a local attacker to arbitrary file creation and execution without click file transfer menu. It is possible to file in arbitrary directory for user because the viewer program receive the file from agent with privilege of administrator.
References
Link | Resource |
---|---|
https://www.boho.or.kr/krcert/secNoticeView.do?bulletin_writing_sequence=36303 | Third Party Advisory |
Configurations
Information
Published : 2021-10-26 18:15
Updated : 2021-10-28 18:20
NVD link : CVE-2020-7867
Mitre link : CVE-2020-7867
JSON object : View
CWE
CWE-20
Improper Input Validation
Products Affected
helpu
- helpuviewer