Description
In Code42 Enterprise and Crashplan for Small Business through Client version 6.9.1, an attacker can craft a restore request to restore a file through the Code42 app to a location they do not have privileges to write.
References (1)
Core 1
Core References
Various Sources x_refsource_confirm
https://code42.com/r/support/CVE-2019-11551
Scores
CVSS v3
5.5
EPSS
0.0025
EPSS Percentile
16.7%
Attack Vector
LOCAL
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
Details
CWE
CWE-269
Status
published
Products (2)
code42/code42_for_enterprise
< 6.9.1
code42/crashplan_for_small_business
< 6.9.1
Published
Aug 21, 2019
Tracked Since
Feb 18, 2026