HIGH7.5
GHSA-q7hx-mrv5-6mrp
HashBrown CMS Directory Traversal
Quick fix
GHSA-q7hx-mrv5-6mrp — hashbrown-cms: upgrade to the fixed version with the command below.
npm install hashbrown-cms@1.3.2Details
An issue was discovered in HashBrown CMS before 1.3.2. `Server/Entity/Resource/Connection.js` allows an attacker to reach a parent directory via a crafted name or ID field.
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://nvd.nist.gov/vuln/detail/CVE-2020-5840[ADVISORY]
- https://github.com/HashBrownCMS/hashbrown-cms/commit/6b37b73944447bb29c6aaeb086b04196d80c692a[WEB]
- https://github.com/HashBrownCMS/hashbrown-cms[PACKAGE]
- https://github.com/HashBrownCMS/hashbrown-cms/compare/v1.3.1...v1.3.2[WEB]
- https://github.com/HashBrownCMS/hashbrown-cms/releases/tag/v1.3.2[WEB]