CVE-2019-12276

Severity CVSS v4.0:
Pending analysis
Type:
CWE-22 Path Traversal
Publication date:
05/06/2019
Last modified:
24/06/2019

Description

A Path Traversal vulnerability in Controllers/LetsEncryptController.cs in LetsEncryptController in GrandNode 4.40 allows remote, unauthenticated attackers to retrieve arbitrary files on the web server via specially crafted LetsEncrypt/Index?fileName= HTTP requests. A patch for this issue was made on 2019-05-30 in GrandNode 4.40.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:grandnode:grandnode:4.40:*:*:*:*:*:*:*