GHSA-536p-4pcj-5mr9
Dashboard / Vulnerabilities / GHSA-536p-4pcj-5mr9
Summary: raspap-webgui in RaspAP 2.6.6 allows attackers to execute commands as root because of the insecure sudoers permissions.
Details: raspap-webgui in RaspAP 2.6.6 allows attackers to execute commands as root because of the insecure sudoers permissions. The www-data account can execute /etc/raspap/hostapd/enablelog.sh as root with no password; however, the www-data account can also overwrite /etc/raspap/hostapd/enablelog.sh with any executable content.
References: https://nvd.nist.gov/vuln/detail/CVE-2021-38557, https://github.com/RaspAP/raspap-webgui, https://github.com/RaspAP/raspap-webgui/blob/fabc48c7daae4013b9888f266332e510b196a062/installers/raspap.sudoers, https://zerosecuritypenetrationtesting.com/?page_id=306
Affected packages
Package
Name: billz/raspap-webgui
Purl: pkg:composer/billz/raspap-webgui
Affected ranges
Type: ECOSYSTEM
Events:
