Filtered by vendor Dgtl Subscriptions
Filtered by product Huemagic Subscriptions
Total 2 CVE
CVE Vendors Products Updated CVSS v3.1
CVE-2021-26504 1 Dgtl 1 Huemagic 2024-10-09 7.5 High
Directory Traversal vulnerability in Foddy node-red-contrib-huemagic version 3.0.0, allows remote attackers to gain sensitive information via crafted request in res.sendFile API in hue-magic.js.
CVE-2021-25864 1 Dgtl 1 Huemagic 2024-08-03 7.5 High
node-red-contrib-huemagic 3.0.0 is affected by hue/assets/..%2F Directory Traversal.in the res.sendFile API, used in file hue-magic.js, to fetch an arbitrary file.