vendor:
CyberPlanet
by:
Cristian Ayala G
6.8
CVSS
MEDIUM
Unquoted Service Path
428
CWE
Product Name: CyberPlanet
Affected Version From: 6.4.0131
Affected Version To: 6.4.0131
Patch Exists: NO
Related CWE:
CPE: a:tenaxsoft:cyberplanet:6.4.131
Platforms Tested: Windows 10 Pro x64
2019
TexasSoft CyberPlanet 6.4.131 – ‘CCSrvProxy’ Unquoted Service Path
The 'CCSrvProxy' service in TexasSoft CyberPlanet 6.4.131 has an unquoted service path vulnerability, which could allow an attacker to escalate privileges and execute arbitrary code.
Mitigation:
To mitigate this vulnerability, the vendor should update the service configuration to include double quotes around the service path. Users can also manually update the service path to include double quotes.