Improper Data Access Privileges in FACSChorus Software

Improper Data Access Privileges in FACSChorus Software

CVE-2023-29066 · LOW Severity

CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L

The FACSChorus software does not properly assign data access privileges for operating system user accounts. A non-administrative OS account can modify information stored in the local application data folders.

Learn more about our User Device Pen Test.