vendor:
GrandNode
by:
Corey Robinson
7.5
CVSS
HIGH
Path Traversal & Arbitrary File Download
22
CWE
Product Name: GrandNode
Affected Version From: <= v4.40 (before 5/30/2019)
Affected Version To: <= v4.40 (before 5/30/2019)
Patch Exists: YES
Related CWE: CVE-2019-12276
CPE: a:grandnode:grandnode
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Ubuntu 18.04
2019
GrandNode Path Traversal & Arbitrary File Download (Unauthenticated)
A path traversal vulnerability in the LetsEncryptController allows remote unauthenticated users to view any files that the application has read/view permissions to. This vulnerability affects Windows and Unix operating systems.
Mitigation:
Ensure that the application is not vulnerable to path traversal attacks by validating user input and restricting access to sensitive files.