Description
An attacker can include file contents from outside the `/adapter/xxx/` directory, where `xxx` is the name of an existent adapter like "admin". It is exploited using the administrative web panel with a request for an adapter file. **Note:** The attacker has to be logged in if the authentication is enabled (by default isn't enabled).
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2019-0788 | An attacker can include file contents from outside the `/adapter/xxx/` directory, where `xxx` is the name of an existent adapter like "admin". It is exploited using the administrative web panel with a request for an adapter file. **Note:** The attacker has to be logged in if the authentication is enabled (by default isn't enabled). |
Github GHSA |
GHSA-cmch-296j-wfvw | Arbitrary File Write in iobroker.js-controller |
References
History
No history.
Status: PUBLISHED
Assigner: snyk
Published:
Updated: 2024-08-04T22:32:01.573Z
Reserved: 2019-04-03T00:00:00.000Z
Link: CVE-2019-10767
No data.
Status : Modified
Published: 2019-11-21T17:15:11.350
Modified: 2024-11-21T04:19:52.933
Link: CVE-2019-10767
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA