CVE-2023-29586
MEDIUMCode Sector TeraCopy 3.9.7 - Arbitrary File Read via Improper Access Control
Title source: llmDescription
Code Sector TeraCopy 3.9.7 does not perform proper access validation on the source folder during a copy operation. This leads to Arbitrary File Read by allowing any user to copy any directory in the system to a directory they control. NOTE: the Supplier disputes this because only admin users can copy arbitrary folders, and because the 143984 reference is about a different concern (unrelated to directory copying) that was fixed in 3.5b.
References (4)
Core 4
Core References
Various Sources
https://www.youtube.com/watch?v=mrOHtWWFhJI
Scores
CVSS v3
5.5
EPSS
0.0032
EPSS Percentile
23.4%
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
partial
Details
CWE
CWE-284
Status
published
Products (1)
codesector/teracopy
3.9.7
Published
Apr 19, 2023
Tracked Since
Feb 18, 2026