← Back

CVE-2019-12162

nvd nist
Published: Jul 23, 2019Modified: Jun 17, 2026

JSON object

Loading...
7.8
Vector
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Exploitability: 1.8 / Impact: 5.9
Source: NVD

Description

Upwork Time Tracker 5.2.2.716 doesn't verify the SHA256 hash of the downloaded program update before running it, which could lead to code execution or local privilege escalation by replacing the original update.exe.

Affected (1)

Products: Upwork: Time Tracker
1 product
Time Tracker
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
Version 5.2.2.716

References (4)

Source: cve@mitre.org
ProductVendor Advisory
Source: cve@mitre.org
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
ProductVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory

Timeline

No history available yet.