Liran Tal 4/27/2023

Disclosing a local file inclusion vulnerability in xmlhttprequest library

Read Original

This article details a security vulnerability (CWE-276) in the xmlhttprequest npm library, version 1.8.0. The flaw, stemming from incorrect default permissions, enables Local File Inclusion (LFI) where an attacker-controlled URL can lead to arbitrary file read access on the server's filesystem. It includes proof-of-concept code and discusses the maintainer's response.

Disclosing a local file inclusion vulnerability in xmlhttprequest library

Comments

No comments yet

Be the first to share your thoughts!

Browser Extension

Get instant access to AllDevBlogs from your browser

Top of the Week