- Description
- The Security Manager in razorCMS before 0.4 does not verify the permissions of every file owned by the apache user account, which is inconsistent with the documentation and allows local users to have an unspecified impact.
- Source
- cve@mitre.org
- NVD status
- Modified
CVSS 2.0
- Type
- Primary
- Base score
- 7.2
- Impact score
- 10
- Exploitability score
- 3.9
- Vector string
- AV:L/AC:L/Au:N/C:C/I:C/A:C
- nvd@nist.gov
- CWE-264
- Hype score
- Not currently trending
[
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:razorcms:razorcms:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "52856284-CC33-4779-8A9D-A9A02FEA6654",
"versionEndIncluding": "0.3"
},
{
"criteria": "cpe:2.3:a:razorcms:razorcms:0.2:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "5D9EDF45-CA3B-44B8-A87E-99083223007C"
},
{
"criteria": "cpe:2.3:a:razorcms:razorcms:0.3:rc2:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "F5B19BB3-8D38-4D4A-928E-75A45A63D6E6"
}
],
"operator": "OR"
}
]
}
]