CVE-2023-29066
28.11.2023, 21:15
The FACSChorus software does not properly assign data access privileges for operating system user accounts. A non-administrative OS account can modify information stored in the local application data folders.Enginsight
| Vendor | Product | Version |
|---|---|---|
| bd | facschorus | 5.0 |
| bd | facschorus | 5.1 |
| bd | facschorus | 3.0 |
| bd | facschorus | 3.1 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
- CWE-266 - Incorrect Privilege AssignmentA product incorrectly assigns a privilege to a particular actor, creating an unintended sphere of control for that actor.
- CWE-269 - Improper Privilege ManagementThe software does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.