Description
SECUDOS Qiata (DOMOS OS) 4.13 has Insecure Permissions for the previewRm.sh daily cronjob. To exploit this, an attacker needs access as a low-privileged user to the underlying DOMOS system. Every user on the system has write permission for previewRm.sh, which is executed by the root user.
Exploits (1)
References (1)
Core 1
Core References
Exploit, Third Party Advisory
https://github.com/vianic/CVE-2023-40361/blob/main/advisory/advisory.md
Scores
CVSS v3
7.8
EPSS
0.0006
EPSS Percentile
18.4%
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CISA SSVC
Vulnrichment
Exploitation
poc
Automatable
no
Technical Impact
total
Details
CWE
CWE-732
Status
published
Products (1)
secudos/qiata
4.13
Published
Oct 20, 2023
Tracked Since
Feb 18, 2026