A vulnerability was found in Weaver E-cology allows attackers use race conditions to bypass security mechanisms to upload malicious files and control server privileges
The product contains a concurrent code sequence that requires temporary, exclusive access to a shared resource, but a timing window exists in which the shared resource can be modified by another code sequence operating concurrently.
Link | Tags |
---|---|
https://github.com/stuven1989/TemporaryGuild/blob/main/guild2.md | broken link |
https://gist.github.com/CoinIsMoney/5dd555805e8f974630ced8a1df8182f1 | third party advisory |