mirror of
https://github.com/0xMarcio/cve.git
synced 2026-06-03 08:48:00 +02:00
758 B
758 B
CVE-2021-26504
Description
Directory Traversal vulnerability in Foddy node-red-contrib-huemagic version 3.0.0, allows remote attackers to gain sensitive information via crafted request in res.sendFile API in hue-magic.js.
POC
Reference
- https://github.com/Foddy/node-red-contrib-huemagic/issues/217
- https://github.com/Foddy/node-red-contrib-huemagic/issues/217