Vulnerabilities > CVE-2021-41066 - Missing Authorization vulnerability in Bopsoft Listary

047910
CVSS 7.5 - HIGH
Attack vector
NETWORK
Attack complexity
HIGH
Privileges required
NONE
Confidentiality impact
HIGH
Integrity impact
HIGH
Availability impact
HIGH
network
high complexity
bopsoft
CWE-862

Summary

An issue was discovered in Listary through 6. When Listary is configured as admin, Listary will not ask for permissions again if a user tries to access files on the system from Listary itself (it will bypass UAC protection; there is no privilege validation of the current user that runs via Listary).

Vulnerable Configurations

Part Description Count
Application
Bopsoft
1

Common Weakness Enumeration (CWE)