VYPR
High severity7.5NVD Advisory· Published Jun 5, 2019· Updated Jun 17, 2026

CVE-2019-12276

CVE-2019-12276

Description

A Path Traversal vulnerability in Controllers/LetsEncryptController.cs in LetsEncryptController in GrandNode 4.40 allows remote, unauthenticated attackers to retrieve arbitrary files on the web server via specially crafted LetsEncrypt/Index?fileName= HTTP requests. A patch for this issue was made on 2019-05-30 in GrandNode 4.40.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

3
  • cpe:2.3:a:grandnode:grandnode:4.40:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:grandnode:grandnode:4.40:*:*:*:*:*:*:*
    • (no CPE)range: 4.40
  • GrandNode/GrandNodedescription

Patches

Vulnerability mechanics

References

2

News mentions

0

No linked articles in our index yet.