|
|||
Rule General Information |
---|
Release Date: | 2020-05-14 | |
Rule Name: | GrandNode Ecommerce LetsEncryptController Directory Traversal Vulnerability (CVE-2019-12276) | |
Severity: | ||
CVE ID: | ||
Rule Protection Details |
---|
Description: | A Path Traversal vulnerability in Controllers/LetsEncryptController.cs in LetsEncryptController in GrandNode 4.40 allows remote, unauthenticated attackers to retrieve arbitrary files on the web server via specially crafted LetsEncrypt/Index?fileName= HTTP requests. A patch for this issue was made on 2019-05-30 in GrandNode 4.40. | |
Impact: | An attacker can abtain sensitive information of the target victim, and do malicious actions to gain profits using the information. | |
Affected OS: | Windows, Linux, Mac OS | |
Reference: | http://packetstormsecurity.com/files/153373/GrandNode-4.40-Path-Traversal-File-Download.html https://github.com/grandnode/grandnode https://grandnode.com |
|
Solutions |
---|
The vendors have released upgrade patches to fix vulnerabilities, please visit: https://grandnode.com/ |