CVE-2019-11552: CODE42 For Enterprise
High severity, CVSS 7.0. EPSS: 0.5% chance of exploitation in the next 30 days.
Code42 Enterprise and Crashplan for Small Business Client version 6.7 before 6.7.5, 6.8 before 6.8.8, and 6.9 before 6.9.4 allows eval injection. A proxy auto-configuration file, crafted by a lesser privileged user, may be used to execute arbitrary code at a higher privilege as the service user.
Affected products
- CODE42 CODE42 For Enterprise: from 6.7, before 6.7.5 (fixed in 6.7.5); from 6.8, before 6.8.8 (fixed in 6.8.8); from 6.9, before 6.9.4 (fixed in 6.9.4)
- CODE42 Crashplan For Small Business: from 6.7, before 6.7.5 (fixed in 6.7.5); from 6.8, before 6.8.8 (fixed in 6.8.8); from 6.9, before 6.9.4 (fixed in 6.9.4)
Published 2019-07-19. Last modified 2026-06-17.