VDB
Sign up
HIGH

GHSA-rq9r-qvwg-829q

Erxes Path Traversal vulnerability

Quick fix

GHSA-rq9r-qvwg-829q — erxes: upgrade to the fixed version with the command below.

npm install erxes@1.6.2

Details

In Erxes <1.6.2, an unauthenticated attacker can read arbitrary files from the system using a Path Traversal vulnerability in the /read-file endpoint handler.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/erxes
Introduced in: 0Fixed in: 1.6.2
Fixnpm install erxes@1.6.2

References