Local File Modification Vulnerability in OnionShare by Micah Lee
CVE-2016-5026

5.5MEDIUM

Key Information:

Vendor

Onionshare

Vendor
CVE Published:
30 January 2017

What is CVE-2016-5026?

A local file modification vulnerability exists in OnionShare versions before 0.9.1, allowing users to manipulate the hidden service by pre-creating the /tmp/onionshare directory. This weakness can lead to unauthorized changes and potential privacy risks for users relying on OnionShare for secure file sharing. Attackers with local access can exploit this vulnerability to tamper with the application's operations, highlighting the importance of applying the latest patches and securing local environments.

References

CVSS V3.1

Score:
5.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.