NodeBB Plugin Emoji 3.2.1 - Arbitrary File Write
Vulnerability Description
NodeBB Plugin Emoji 3.2.1 contains an arbitrary file write vulnerability that allows administrative users to write files to arbitrary system locations through the emoji upload API. Attackers with admin access can craft file upload requests with directory traversal to overwrite system files by manipulating the file path parameter.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2021-47746
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- 1F98D
References
More from NodeBB
View All →Affected Vendor
NodeBB
View all reports →