vendor:
Socket.io-file
by:
Cr0wTom
7.5
CVSS
HIGH
Improper Input Validation in File Upload Functionality
20
CWE
Product Name: Socket.io-file
Affected Version From: <= v2.0.31
Affected Version To: N/A
Patch Exists: YES
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: node v10.19.0, Socket.io-file v2.0.31, socket.io v2.3.0
2020
Socket.io-file 2.0.31 – Arbitrary File Upload
Socket.io-file is vulnerable to an improper input validation in the file upload functionality. An attacker can exploit this vulnerability to upload arbitrary files to the server.
Mitigation:
Upgrade to the latest version of Socket.io-file