RaspAP before 3.1.5 allows an attacker to escalate privileges: the www-data user has write access to the restapi.service file and also possesses Sudo privileges to execute several critical commands without a password.
{
"nvd_published_at": "2024-07-29T06:15:02Z",
"github_reviewed_at": "2024-07-29T17:01:23Z",
"cwe_ids": [
"CWE-269",
"CWE-77"
],
"severity": "CRITICAL",
"github_reviewed": true
}