Local Privilege Escalation: Arbitrary Application Deletion in Galaxy Themes Service

Local Privilege Escalation: Arbitrary Application Deletion in Galaxy Themes Service

CVE-2023-30643 · HIGH Severity

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H

Missing authentication vulnerability in Galaxy Themes Service prior to SMR Jul-2023 Release 1 allows local attackers to delete arbitrary non-preloaded applications.

Learn more about our Web Application Penetration Testing UK.