mirror of
https://github.com/0xMarcio/cve.git
synced 2026-05-29 20:39:28 +02:00
758 B
758 B
CVE-2021-26504
Description
Directory Traversal vulnerability in Foddy node-red-contrib-huemagic version 3.0.0, allows remote attackers to gain sensitive information via crafted request in res.sendFile API in hue-magic.js.
POC
Reference
- https://github.com/Foddy/node-red-contrib-huemagic/issues/217
- https://github.com/Foddy/node-red-contrib-huemagic/issues/217