Soyal Technologies SOYAL 701Server 9.0.1 suffers from an elevation of privileges vulnerability which can be used by an authenticated user to change the executable file with a binary choice. The vulnerability is due to improper permissions with the 'F' flag (Full) for 'Everyone'and 'Authenticated Users' group.
During installation, installed file permissions are set to allow anyone to modify those files.
Link | Tags |
---|---|
https://www.zeroscience.mk/en/vulnerabilities | third party advisory exploit |
https://www.exploit-db.com/exploits/49678 | exploit vdb entry third party advisory |
https://www.zeroscience.mk/en/vulnerabilities/ZSL-2021-5633.php | third party advisory exploit |