Liran Tal 4/27/2023

Disclosing a local file inclusion vulnerability in xmlhttprequest library

Read Original

This article details a security vulnerability (CWE-276) in the xmlhttprequest npm library, version 1.8.0. The flaw, stemming from incorrect default permissions, enables Local File Inclusion (LFI) where an attacker-controlled URL can lead to arbitrary file read access on the server's filesystem. It includes proof-of-concept code and discusses the maintainer's response.

Disclosing a local file inclusion vulnerability in xmlhttprequest library

Comments

No comments yet

Be the first to share your thoughts!

Browser Extension

Get instant access to AllDevBlogs from your browser