mirror of
https://github.com/0xMarcio/cve.git
synced 2026-05-26 13:37:50 +02:00
20 lines
838 B
Markdown
20 lines
838 B
Markdown
### [CVE-2021-43043](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-43043)
|
|

|
|

|
|

|
|
|
|
### Description
|
|
|
|
An issue was discovered in Kaseya Unitrends Backup Appliance before 10.5.5. The apache user could read arbitrary files such as /etc/shadow by abusing an insecure Sudo rule.
|
|
|
|
### POC
|
|
|
|
#### Reference
|
|
- https://helpdesk.kaseya.com/hc/en-gb/articles/4412762258961
|
|
- https://www.cyberonesecurity.com/blog/exploiting-kaseya-unitrends-backup-appliance-part-1
|
|
- https://www.cyberonesecurity.com/blog/exploiting-kaseya-unitrends-backup-appliance-part-2
|
|
|
|
#### Github
|
|
No PoCs found on GitHub currently.
|
|
|