Insecure Permissions for previewRm.sh Cronjob in SECUDOS Qiata (DOMOS OS) 4.13

Insecure Permissions for previewRm.sh Cronjob in SECUDOS Qiata (DOMOS OS) 4.13

CVE-2023-40361 · HIGH Severity

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

SECUDOS Qiata (DOMOS OS) 4.13 has Insecure Permissions for the previewRm.sh daily cronjob. To exploit this, an attacker needs access as a low-privileged user to the underlying DOMOS system. Every user on the system has write permission for previewRm.sh, which is executed by the root user.

Learn more about our User Device Pen Test.