XINJE XDPPro.exe
cpe:2.3:a:xinje:xdppro:*:*:*:*:*:*:*
- >= 3.2.2, <= 3.7.17c
A vulnerability exists in the XNetSocketClient component of XINJE XDPPro.exe, specifically in versions 3.2.2 to 3.7.17c. The issue arises from insecure permissions that allow attackers to execute arbitrary code by modifying the application's configuration file.
Exploitation of this vulnerability could lead to unauthorized execution of code within the context of the user running the application.
To reproduce this vulnerability, first install XINJE XDPPro.exe version 3.2.2 to 3.7.17c. Once installed, navigate to the application's configuration file. Due to the insecure permissions, an unauthorized user can modify this file. After making changes, the application can be launched, executing the injected code or commands.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.