An issue in trojan v.2.0.0 through v.2.15.3 allows a remote attacker to escalate privileges via the initialization interface /auth/register.
During installation, installed file permissions are set to allow anyone to modify those files.
Link | Tags |
---|---|
https://github.com/ainrm/Jrohy-trojan-unauth-poc/blob/main/README.en.md | exploit third party advisory |