Vulnerabilities (CVE)

Filtered by vendor Grandnode Subscribe
Filtered by product Grandnode
Total 1 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2019-12276 1 Grandnode 1 Grandnode 2024-11-21 5.0 MEDIUM 7.5 HIGH
A Path Traversal vulnerability in Controllers/LetsEncryptController.cs in LetsEncryptController in GrandNode 4.40 allows remote, unauthenticated attackers to retrieve arbitrary files on the web server via specially crafted LetsEncrypt/Index?fileName= HTTP requests. A patch for this issue was made on 2019-05-30 in GrandNode 4.40.