Vulnerabilities > CVE-2021-28119 - Unspecified vulnerability in Twinkletray Twinkle Tray

047910
CVSS 9.8 - CRITICAL
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
HIGH
Integrity impact
HIGH
Availability impact
HIGH
network
low complexity
twinkletray
critical

Summary

Twinkle Tray (aka twinkle-tray) through 1.13.3 allows remote command execution. A remote attacker may send a crafted IPC message to the exposed vulnerable ipcRenderer IPC interface, which invokes the dangerous openExternal API.

Vulnerable Configurations

Part Description Count
Application
Twinkletray
56