CRITICAL9.9
GHSA-q623-2j2j-23jj
RaspAP allows an attacker to escalate privileges
Details
RaspAP before 3.1.5 allows an attacker to escalate privileges: the www-data user has write access to the restapi.service file and also possesses Sudo privileges to execute several critical commands without a password.
Are you affected?
Enter the version of the package you're using.
Affected packages
Packagist/billz/raspap-webgui
Introduced in:
0No fixed version published yet for billz/raspap-webgui (composer). Pin to a known-safe version or switch to an alternative.