CVE-2023-29066
28.11.2023, 21:15
The FACSChorus software does not properly assign data access privileges for operating system user accounts. A non-administrative OS account can modify information stored in the local application data folders.Enginsight
Vendor | Product | Version |
---|---|---|
bd | facschorus | 5.0 |
bd | facschorus | 5.1 |
bd | facschorus | 3.0 |
bd | facschorus | 3.1 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
- CWE-266 - Incorrect Privilege AssignmentA product incorrectly assigns a privilege to a particular actor, creating an unintended sphere of control for that actor.
- CWE-269 - Improper Privilege ManagementThe software does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.