In Code42 Enterprise and Crashplan for Small Business through Client version 6.9.1, an attacker can craft a restore request to restore a file through the Code42 app to a location they do not have privileges to write.
The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Code42_for_enterprise | Code42 | * | 6.9.1 (including) |
Crashplan_for_small_business | Code42 | * | 6.9.1 (including) |