CVE-2023-29586

MEDIUM

Code Sector TeraCopy 3.9.7 - Arbitrary File Read via Improper Access Control

Title source: llm
STIX 2.1

Description

Code Sector TeraCopy 3.9.7 does not perform proper access validation on the source folder during a copy operation. This leads to Arbitrary File Read by allowing any user to copy any directory in the system to a directory they control. NOTE: the Supplier disputes this because only admin users can copy arbitrary folders, and because the 143984 reference is about a different concern (unrelated to directory copying) that was fixed in 3.5b.

Scores

CVSS v3 5.5
EPSS 0.0032
EPSS Percentile 23.4%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-284
Status published
Products (1)
codesector/teracopy 3.9.7
Published Apr 19, 2023
Tracked Since Feb 18, 2026