Vulnerabilities > V2Rayl Project

DATE CVE VULNERABILITY TITLE RISK
2020-03-15 CVE-2020-10589 Improper Privilege Management vulnerability in V2Rayl Project V2Rayl 2.1.3
v2rayL 2.1.3 allows local users to achieve root access because /etc/v2rayL/config.json is owned by a low-privileged user but contains commands that are executed as root, after v2rayL.service is restarted via Sudo.
local
low complexity
v2rayl-project CWE-269
7.8
2020-03-15 CVE-2020-10588 Improper Privilege Management vulnerability in V2Rayl Project V2Rayl 2.1.3
v2rayL 2.1.3 allows local users to achieve root access because /etc/v2rayL/add.sh and /etc/v2rayL/remove.sh are owned by a low-privileged user but execute as root via Sudo.
local
low complexity
v2rayl-project CWE-269
7.8