CVE-2020-10588
15.03.2020, 21:15
v2rayL 2.1.3 allows local users to achieve root access because /etc/v2rayL/add.sh and /etc/v2rayL/remove.sh are owned by a low-privileged user but execute as root via Sudo.Enginsight
Vendor | Product | Version |
---|---|---|
v2rayl_project | v2rayl | 2.1.3 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration