vendor:
XAMPP
by:
Salman Asad (LeoBreaker)
8,8
CVSS
HIGH
Local Privilege Escalation
264
CWE
Product Name: XAMPP
Affected Version From: XAMPP < 7.2.29, 7.3.x < 7.3.16 & 7.4.x < 7.4.4
Affected Version To: N/A
Patch Exists: YES
Related CWE: CVE-2020-11107
CPE: a:apache:xampp
Metasploit:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows 10
2021
XAMPP 7.4.3 – Local Privilege Escalation
XAMPP versions < 7.2.29, 7.3.x < 7.3.16 & 7.4.x < 7.4.4 are vulnerable to local privilege escalation. An attacker can exploit this vulnerability by replacing the xampp-control.ini file with a malicious payload. This will allow the attacker to gain elevated privileges on the system.
Mitigation:
Upgrade to the latest version of XAMPP to mitigate this vulnerability.