CVE-2019-12276

A Path Traversal vulnerability in Controllers/LetsEncryptController.cs in LetsEncryptController in GrandNode 4.40 allows remote, unauthenticated attackers to retrieve arbitrary files on the web server via specially crafted LetsEncrypt/Index?fileName= HTTP requests. A patch for this issue was made on 2019-05-30 in GrandNode 4.40.
Configurations

Configuration 1

cpe:2.3:a:grandnode:grandnode:4.40:*:*:*:*:*:*:*

Information

Published : 2019-06-05 06:29

Updated : 2019-06-24 11:15


NVD link : CVE-2019-12276

Mitre link : CVE-2019-12276

Products Affected
No products.
CWE