CVE-2019-11551

Severity CVSS v4.0:
Pending analysis
Type:
CWE-269 Improper Privilege Management
Publication date:
21/08/2019
Last modified:
24/08/2020

Description

In Code42 Enterprise and Crashplan for Small Business through Client version 6.9.1, an attacker can craft a restore request to restore a file through the Code42 app to a location they do not have privileges to write.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:code42:code42_for_enterprise:*:*:*:*:*:*:*:* 6.9.1 (including)
cpe:2.3:a:code42:crashplan_for_small_business:*:*:*:*:*:*:*:* 6.9.1 (including)


References to Advisories, Solutions, and Tools