Path Traversal Vulnerability in HTML-Pages Node Module by Daniel Cardoso
CVE-2018-3744

9.8CRITICAL

Key Information:

Vendor

Hackerone

Vendor
CVE Published:
29 May 2018

What is CVE-2018-3744?

The HTML-Pages Node module contains a path traversal vulnerability that could be exploited by attackers to access sensitive files on the server via cURL. This weakness allows unauthorized reading of files, potentially exposing critical data and system configurations to malicious actors. Ensuring proper validation and sanitization of file paths is essential to mitigate this risk.

Affected Version(s)

html-pages node module Not fixed

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.