Q-Free MaxTime Path Traversal Vulnerability Allowing File Overwrite
Vulnerability
A path traversal vulnerability has been identified in Q-Free MaxTime versions through 2.11.0. The issue resides in the maxtime/api/database/database.lua file, specifically within the setActive endpoint. This vulnerability allows authenticated remote attackers to overwrite sensitive files by sending crafted HTTP requests.
Impact
Exploitation of this vulnerability could lead to unauthorized overwriting of sensitive files, causing data corruption or allowing privilege escalation.
Remediation
No official solution has been communicated by the vendor. However, it is recommended to restrict and monitor network access to the management web application on devices running Q-Free MaxTime versions through 2.11.0, until a patch is released.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
