Fortra Digital Guardian Agent Uninstaller Cross Site Scripting / UninstallKey Cached

Discussion in 'News Aggregator' started by Packet Storm, 29 Nov 2023.

  1. Packet Storm

    Packet Storm Guest

    The uninstaller in Fortra Digital Guardian Agent versions prior to 7.9.4 suffers from a cross site scripting vulnerability. Additionally, the Agent Uninstaller handles sensitive data insecurely and caches the Uninstall key in memory. This key can be used to stop or uninstall the application. This allows a locally authenticated attacker with administrative privileges to disable the application temporarily or even remove the application from the system completely.

    Continue reading...
     

Share This Page

Loading...