You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Sorry but I don't understand why this is a security issue. Users install Seafile client in system directories. The attacker has to first have the permission to write to the system directories. And it's usual for applications to load dlls. There are a lot of dll files in Seafile, why only is this one dangerous?
DLL: exchndl.dll
Affected Process: seaf-daemon.exe
Tested on: Windows 10 Pro x64 Version 10.0.19041
Description:
Seafile Client ver 7.0.8 is vulnerable to DLL hijacking because it loads “exchndl.dll” from the current working directory.
Steps to reproduce:
PoC Code:
Screenshots:
The text was updated successfully, but these errors were encountered: