CVE-2019-12276
grandnode grandnode Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
Record summary
CVE-2019-12276 has a selected CVSS score of 7.5 (high); EIP currently links 1 catalogued exploit and 1 Nuclei template.
Description
A Path Traversal vulnerability in Controllers/LetsEncryptController.cs in LetsEncryptController in GrandNode 4.40 allows remote, unauthenticated attackers to retrieve arbitrary files on the web server via specially crafted LetsEncrypt/Index?fileName= HTTP requests. A patch for this issue was made on 2019-05-30 in GrandNode 4.40.
Exploitation context
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
grandnodeBrowse grandnode / grandnode | VulnCheck | Version data not supplied | |
Proofs of concept
1Catalogued exploits
ExploitDBGrandNode 4.40 - Path Traversal / Arbitrary File DownloadExploitDB exploitby Corey RobinsonNot analyzed1 file
Nuclei templates
1ProjectDiscoveryHIGHGrandNode 4.40 - Local File InclusionCVSS 7.5
GrandNode 4.40 is susceptible to local file inclusion in Controllers/LetsEncryptController.cs, which allows remote unauthenticated attackers to retrieve arbitrary files on the web server via specially crafted LetsEncrypt/Index?fileName= HTTP requests.
Impact
Successful exploitation of this vulnerability can lead to unauthorized access to sensitive information, remote code execution, and potential compromise of the entire system.
Remediation
A patch for this issue was made on 2019-05-30 in GrandNode 4.40.
Source: ProjectDiscovery