Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Upwork Time Tracker 5.2.2.716 doesn't verify the SHA256 hash of the downloaded program update before running it, which could lead to code execution or local privilege escalation by replacing the original update.exe.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Upwork Time Tracker 权限许可和访问控制问题漏洞
Vulnerability Description
Upwork Time Tracker是一套适用于自由职业者的工作时间跟踪解决方案。 Upwork Time Tracker 5.2.2.716版本中存在安全漏洞,该漏洞源于程序在运行下载的程序时,没有验证改程序的SHA256散列。攻击者可通过替换原有的update.exe文件利用该漏洞执行代码或提升权限。
CVSS Information
N/A
Vulnerability Type
N/A