RaspAP before 3.1.5 allows an attacker to escalate privileges: the www-data user has write access to the restapi.service file and also possesses Sudo privileges to execute several critical commands without a password.
| Package (Ecosystem) | Introduced | Fixed | Limit |
|---|---|---|---|
| billz/raspap-webgui(Packagist) | 0 | N/A | N/A |
CVSS Metrics