Security Advisory

CVE-2019-11552

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2019-07-19 13:51:23
Last updated 2024-08-04 22:55:40
Assigner mitre
CVSS score not scored
State PUBLISHED

Description

Code42 Enterprise and Crashplan for Small Business Client version 6.7 before 6.7.5, 6.8 before 6.8.8, and 6.9 before 6.9.4 allows eval injection. A proxy auto-configuration file, crafted by a lesser privileged user, may be used to execute arbitrary code at a higher privilege as the service user.