Path Traversal in localhost-now
High severity
GitHub Reviewed
Published
Jun 11, 2019
to the GitHub Advisory Database
•
Updated Jan 9, 2023
Description
Reviewed
Jun 11, 2019
Published to the GitHub Advisory Database
Jun 11, 2019
Last updated
Jan 9, 2023
All versions of
localhost-now
are vulnerable to path traversal. This vulnerability is a bypass to the path traversal fix introduced in version 1.0.2Proof of concept:
Recommendation
No fix is currently available for this vulnerability. It is our recommendation to not install or use this module until a fix is available.
References