Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:22007
HistoryNov 22, 2019 - 3:16 a.m.

Directory Traversal

2019-11-2203:16:26
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
7

EPSS

0.003

Percentile

68.4%

ioBroker.js-controller is vulnerable to directory traversal. An attacker is able to include file contents from outside of the /adapter/ directory via the administrative web panel using a request for an adapter file containing the ../ characters in the file name. Authentication is not enabled by default and allows unauthenticated access to the administrative web panel.

EPSS

0.003

Percentile

68.4%