Vulnerabilities > 1E > Client > 23.7.1.151

DATE CVE VULNERABILITY TITLE RISK
2023-10-05 CVE-2023-45160 Files or Directories Accessible to External Parties vulnerability in 1E Client
In the affected version of the 1E Client, an ordinary user could subvert downloaded instruction resource files, e.g., to substitute a harmful script.
network
low complexity
1e CWE-552
8.8
2023-10-05 CVE-2023-45159 Link Following vulnerability in 1E Client
1E Client installer can perform arbitrary file deletion on protected files.   A non-privileged user could provide a symbolic link or Windows junction to point to a protected directory in the installer that the 1E Client would then clear on service startup.
local
low complexity
1e CWE-59
8.4