Openmediavault Remote Code Execution / Local Privilege Escalation

Discussion in 'News Aggregator' started by Packet Storm, 10 May 2024.

  1. Packet Storm

    Packet Storm Guest

    Openmediavault versions prior to 7.0.32 have a vulnerability that occurs when users in the web-admin group enter commands on the crontab by selecting the root shell. As a result of exploiting the vulnerability, authenticated web-admin users can run commands with root privileges and receive reverse shell connections.

    Continue reading...
     

Share This Page

Loading...