CVE-2022-33035

Severity CVSS v4.0:
Pending analysis
Type:
CWE-427 Uncontrolled Search Path Element
Publication date:
29/06/2022
Last modified:
08/07/2022

Description

XLPD v7.0.0094 and below contains an unquoted service path vulnerability which allows local users to launch processes with elevated privileges.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:netsarang:xlpd:*:*:*:*:*:*:*:* 7.0.0103 (excluding)