CVE-2021-43788

Severity CVSS v4.0:
Pending analysis
Type:
CWE-22 Path Traversal
Publication date:
29/11/2021
Last modified:
27/10/2022

Description

Nodebb is an open source Node.js based forum software. Prior to v1.18.5, a path traversal vulnerability was present that allowed users to access JSON files outside of the expected `languages/` directory. The vulnerability has been patched as of v1.18.5. Users are advised to upgrade as soon as possible.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:nodebb:nodebb:*:*:*:*:*:*:*:* 1.0.4 (including) 1.18.4 (including)