@saltcorn/server arbitrary file zip read and download when downloading auto backups
Modified: 10/3/2024
package
pkg:npm/%40saltcorn/server
@saltcorn/server arbitrary file zip read and download when downloading auto backups
Modified: 10/3/2024
Saltcorn has an Unauthenticated Path Traversal in sync endpoints, allowing arbitrary file write and directory read
Modified: 4/10/2026
Saltcorn Server allows logged-in users to delete arbitrary files because of a path traversal vulnerability
Modified: 10/8/2024
@saltcorn/server Remote Code Execution (RCE) / SQL injection via prototype pollution by manipulating `lang` and `defstring` parameters when setting localizer strings
Modified: 10/3/2024
@saltcorn/server arbitrary file and directory listing when accessing build mobile app results
Modified: 10/3/2024
Saltcorn's Reflected XSS and Command Injection vulnerabilities can be chained for 1-click-RCE
Modified: 2/3/2026
Saltcorn: Open Redirect in `POST /auth/login` due to incomplete `is_relative_url` validation (backslash bypass)
Modified: 5/11/2026
Saltcorn: SQL Injection via Unparameterized Sync Endpoints (maxLoadedId)
Modified: 5/5/2026
Saltcorn Server Stored Cross-Site Scripting (XSS) in event logs page
Modified: 10/7/2024