Charities.cron 1.0.2 through 1.6.0 allows local users to write to arbitrary files via a symlink attack on temporary files.
| Software | From | Fixed in |
|---|---|---|
| steve_sachs / charities.cron | 1.0.2 | 1.0.2.x |
| steve_sachs / charities.cron | 1.1.1 | 1.1.1.x |
| steve_sachs / charities.cron | 1.6.0 | 1.6.0.x |
| steve_sachs / charities.cron | 1.5.0 | 1.5.0.x |