PT-2019-12039 · Iobroker · Iobroker.Controller

Publicado

2019-11-21

·

Atualizado

2019-12-03

·

CVE-2019-10767

CVSS v3.1

7.5

Alta

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions iobroker.controller versions prior to 2.0.25
Description The issue allows an attacker to include file contents from outside the intended directory using the administrative web panel. This can be exploited by making a request for an adapter file. The attacker must be logged in if authentication is enabled, although authentication is disabled by default.
Recommendations Upgrade to version 2.0.25 or later.

Exploit

Correção

Path traversal

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2019-10767
GHSA-CMCH-296J-WFVW
SNYK-JS-IOBROKERJSCONTROLLER-534881

Produtos afetados

Iobroker.Controller