Allegra saveInlineEdit Directory Traversal Remote Code Execution Vulnerability
CVE-2023-51647
4.7MEDIUM
What is CVE-2023-51647?
The vulnerability in Allegra arises from an improper validation flaw within the saveInlineEdit method, allowing an attacker to specify a user-supplied path that can lead to unauthorized file operations. Although some level of authentication is required for exploitability, the existing authentication controls can be bypassed by an attacker. This permits the execution of arbitrary code under the context of LOCAL SERVICE, which can pose significant risks to the security and integrity of the affected system.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Allegra 7.5.0 build 29
References
CVSS V3.1
Score:
4.7
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
