VDB
Sign up
MEDIUM

GHSA-2977-5php-6789

Erxes Path Traversal vulnerability

Quick fix

GHSA-2977-5php-6789 — erxes: upgrade to the fixed version with the command below.

npm install erxes@1.6.2

Details

In Erxes <1.6.2, an authenticated attacker can write to arbitrary files on the system using a Path Traversal vulnerability in the importHistoriesCreate GraphQL mutation handler.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/erxes
Introduced in: 0Fixed in: 1.6.2
Fixnpm install erxes@1.6.2

References