Impact
Insufficient input validation in Admin By Request (ABR) allows a low-privileged user to inject malicious entries into the sudoers file, giving the attacker persistent root access that remains effective after the ABR session ends. The flaw leads to unauthorized elevation of privileges, enabling the attacker to execute commands with superuser rights and bypass normal security controls.
Affected Systems
The vulnerability affects all versions of Admin By Request (ABR). No specific version information is provided, so all installations of ABR are potentially impacted until updated.
Risk and Exploitability
The CVSS score of 7.8 indicates a high severity. The exploit probability (EPSS) is not available, but the flaw requires only a low-privileged user within ABR to submit crafted input, making it accessible and potentially highly impactful. The vulnerability is not listed in the CISA KEV catalog, but the persistence of root access after the session makes it a significant risk.
OpenCVE Enrichment