vendor:
NodeBB Plugin Emoji
by:
1F98D
7.5
CVSS
HIGH
Arbitrary File Write
264
CWE
Product Name: NodeBB Plugin Emoji
Affected Version From: Emoji for NodeBB <= v3.2.1
Affected Version To: Emoji for NodeBB <= v3.2.1
Patch Exists: NO
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Ubuntu 18.04 (x86)
2021
NodeBB Plugin Emoji 3.2.1 – Arbitrary File Write
The Emoji for NodeBB which is installed by default contains an arbitrary file write vulnerability to insecurely handled user controlled input. This exploit requires administrative access to the NodeBB instance in order to access the emoji upload API.
Mitigation:
Ensure that user input is securely handled and that administrative access is restricted to trusted users.