PT-2019-12039 · Iobroker · Iobroker.Controller

Published

2019-11-21

·

Updated

2019-12-03

·

CVE-2019-10767

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions iobroker.controller versions prior to 2.0.25
Description The issue allows an attacker to include file contents from outside the intended directory using the administrative web panel. This can be exploited by making a request for an adapter file. The attacker must be logged in if authentication is enabled, although authentication is disabled by default.
Recommendations Upgrade to version 2.0.25 or later.

Exploit

Fix

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2019-10767
GHSA-CMCH-296J-WFVW
SNYK-JS-IOBROKERJSCONTROLLER-534881

Affected Products

Iobroker.Controller