VDB
Sign up
HIGH7.5

GHSA-q7hx-mrv5-6mrp

HashBrown CMS Directory Traversal

Quick fix

GHSA-q7hx-mrv5-6mrp — hashbrown-cms: upgrade to the fixed version with the command below.

npm install hashbrown-cms@1.3.2

Details

An issue was discovered in HashBrown CMS before 1.3.2. `Server/Entity/Resource/Connection.js` allows an attacker to reach a parent directory via a crafted name or ID field.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/hashbrown-cms
Introduced in: 0Fixed in: 1.3.2
Fixnpm install hashbrown-cms@1.3.2

References