Vulnerabilidad · Publicado 22/06/2026 · Actualizado 01/08/2026
A path traversal attack when using a "configName" parameter in qSnapper before version 1.3.3 allowed a local attacker to use malicious config files for snapper and so cause a denial of service or potentially escalate privileges to root.
A path traversal attack when using a "configName" parameter in qSnapper before version 1.3.3 allowed a local attacker to use malicious config files for snapper and so cause a denial of service or potentially escalate privileges to root.
Score: 7.3/10 — Severidad: HIGH — Estado NIST: Analyzed
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H
Qsnapper — Presire
CWE-23
Publicado en NIST NVD.