Nishant Jain

5 exploits Active since Jul 2024
CVE-2024-39918 WRITEUP MEDIUM WRITEUP
url-to-png < 2.1.2 - Path Traversal via ImageId Parameter
@jmondi/url-to-png is an open source URL to PNG utility featuring parallel rendering using Playwright for screenshots and with storage caching via Local, S3, or CouchDB. Input of the `ImageId` in the code is not sanitized and may lead to path traversal. This allows an attacker to store an image in an arbitrary location that the server has permission to access. This issue has been addressed in version 2.1.2 and all users are advised to upgrade. There are no known workarounds for this vulnerability.
CVSS 4.3
CVE-2024-39919 WRITEUP LOW WRITEUP
jmondi/url-to-png < 2.1.2 - Exposure of Sensitive Information via Localhost Screenshot Capture
@jmondi/url-to-png is an open source URL to PNG utility featuring parallel rendering using Playwright for screenshots and with storage caching via Local, S3, or CouchDB. The package includes an `ALLOW_LIST` where the host can specify which services the user is permitted to capture screenshots of. By default, capturing screenshots of web services running on localhost, 127.0.0.1, or the [::] is allowed. If someone hosts this project on a server, users could then capture screenshots of other web services running locally. This issue has been addressed in version 2.1.1 with the addition of a blocklist. Users are advised to upgrade. There are no known workarounds for this vulnerability.
CVSS 3.1
CVE-2024-44729 WRITEUP HIGH WRITEUP
Mirotalk <9de226 - Privilege Escalation
Incorrect access control in the component app/src/server.js of Mirotalk before commit 9de226 allows unauthenticated attackers without presenter privileges to arbitrarily eject users from a meeting.
CVSS 7.5
CVE-2024-44730 WRITEUP CRITICAL WRITEUP
Mirotalk - Incorrect Access Control in handleDataChannelChat Function
Incorrect access control in the function handleDataChannelChat(dataMessage) of Mirotalk before commit c21d58 allows attackers to forge chat messages using an arbitrary sender name.
CVSS 9.1
CVE-2024-44731 WRITEUP MEDIUM WRITEUP
Mirotalk - DOM-based Cross-Site Scripting via RTC Message Payload
Mirotalk before commit 9de226 was discovered to contain a DOM-based cross-site scripting (XSS) vulnerability which allows attackers to execute arbitrary code via sending crafted payloads in messages to other users over RTC connections.
CVSS 4.7