Record summary

CVE-2021-25864 has a selected CVSS score of 7.5 (high); EIP currently links 1 Nuclei template.

Description

node-red-contrib-huemagic 3.0.0 is affected by hue/assets/..%2F Directory Traversal.in the res.sendFile API, used in file hue-magic.js, to fetch an arbitrary file.

Description source: CVE List

Exploitation context

Known exploitation

VulnCheck KEV
Listed · Dec 24, 2023 · VulnCheck
Reported exploitation
Observed · VulnCheck

Available material

Nuclei templates
1

Affected products and versions

2
ProductSourceVersion rangeStatus
VulnCheckVersion data not supplied
GitHub AdvisoryThrough 3.0.0affected

Nuclei templates

1
ProjectDiscoveryHIGHHue Magic 3.0.0 - Local File InclusionCVSS 7.5

Hue Magic 3.0.0 is susceptible to local file inclusion via the res.sendFile API.

Impact

The LFI vulnerability can lead to unauthorized access to sensitive files, potentially exposing sensitive information or allowing for further exploitation.

Remediation

Apply the latest security patch or update to a non-vulnerable version of Hue Magic.

WeaknessesCWE-22
Authors0x_Akoko
Template tagscve2021cvehuemagiclfidgtlnode.jsvkevvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CPE: cpe:2.3:a:dgtl:huemagic:3.0.0:*:*:*:*:node.js:*:*
Shodan: title:"NODE-RED"
Shodan: http.title:"node-red"
FOFA: title="node-red"
Google: intitle:"node-red"

Source: ProjectDiscovery

References

3