VDB
Sign up
CRITICAL9.9

GHSA-q623-2j2j-23jj

RaspAP allows an attacker to escalate privileges

Details

RaspAP before 3.1.5 allows an attacker to escalate privileges: the www-data user has write access to the restapi.service file and also possesses Sudo privileges to execute several critical commands without a password.

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist/billz/raspap-webgui
Introduced in: 0

No fixed version published yet for billz/raspap-webgui (composer). Pin to a known-safe version or switch to an alternative.

References