漏洞描述
GrandNode 4.40 is susceptible to local file inclusion in Controllers/LetsEncryptController.cs, which allows remote unauthenticated attackers to retrieve arbitrary files on the web server via specially crafted LetsEncrypt/Index?fileName= HTTP requests.
影响产品
修复建议
建议关注厂商安全公告,及时升级至已修复版本,并结合实际资产暴露情况采取缓解措施。
参考链接
security401.comhttps://security401.com/grandnode-path-traversal/↗grandnode.comhttps://grandnode.com↗github.comhttps://github.com/grandnode/grandnode↗nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2019-12276↗packetstormsecurity.comhttp://packetstormsecurity.com/files/153373/GrandNode-4.40-Path-Traversal-File-Download.html↗