0.49.15
3 years ago
2 days ago
Known vulnerabilities in the changedetection.io package. This does not include vulnerabilities belonging to this package’s dependencies.
Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.
Fix for freeVulnerability | Vulnerable Version |
---|---|
changedetection.io is a Website change detection and monitoring service Affected versions of this package are vulnerable to Directory Traversal on URLs received as input. An attacker can read local files via the watch preview functionality. URLs are not sufficiently checked for paths that traverse directories with a "dot-dot" pattern, paths beginning with a space. How to fix Directory Traversal? Upgrade | [,0.48.5) |
changedetection.io is a Website change detection and monitoring service Affected versions of this package are vulnerable to Directory Traversal due to improper validation for the file Note:
This issue only affects instances with a How to fix Directory Traversal? Upgrade | [,0.47.6) |
changedetection.io is a Website change detection and monitoring service Affected versions of this package are vulnerable to Directory Traversal via the How to fix Directory Traversal? Upgrade | [,0.47.5) |
changedetection.io is a Website change detection and monitoring service Affected versions of this package are vulnerable to Cross-site Scripting (XSS) due to improper sanitization of user input in the How to fix Cross-site Scripting (XSS)? Upgrade | [,0.45.22) |
changedetection.io is a Website change detection and monitoring service Affected versions of this package are vulnerable to Server-Side Template Injection due to improper handling of template data. An attacker can execute arbitrary commands on the server by crafting malicious input that exploits the template rendering process. Notes:
2)This vulnerability is particularly severe as it allows for complete server takeover without any restrictions, such as running a reverse shell. How to fix Server-Side Template Injection? Upgrade | [,0.45.21) |
changedetection.io is a Website change detection and monitoring service Affected versions of this package are vulnerable to Incorrect Authorization via the API endpoint How to fix Incorrect Authorization? Upgrade | [,0.45.13) |
changedetection.io is a Website change detection and monitoring service Affected versions of this package are vulnerable to Cross-site Scripting (XSS) in the main page which allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the URL parameter under the "Add a new change detection watch" function. How to fix Cross-site Scripting (XSS)? Upgrade | [,0.40.2) |