Source |
The Hacker News |
Identifiant |
4434724 |
Date de publication |
2022-04-12 06:08:56 (vue: 2022-04-12 14:07:53) |
Titre |
Critical LFI Vulnerability Reported in Hashnode Blogging Platform |
Texte |
Researchers have disclosed a previously undocumented local file inclusion (LFI) vulnerability in Hashnode, a developer-oriented blogging platform, that could be abused to access sensitive data such as SSH keys, server's IP address, and other network information.
"The LFI originates in a Bulk Markdown Import feature that can be manipulated to provide attackers with unimpeded ability to download |
Notes |
|
Envoyé |
Oui |
Condensat |
ability abused access address attackers a bulk blogging can could critical data developer disclosed download feature that file hashnode have import inclusion information in hashnode keys lfi local manipulated markdown network oriented originates other platform previously provide reported researchers sensitive server ssh such undocumented unimpeded vulnerability |
Tags |
Vulnerability
|
Stories |
|
Move |
|