VYPR

Nodebb

by NodeBB

npm: nodebb

Source repositories

CVEs (21)

  • CVE-2020-15149CriAug 20, 2020
    risk 0.00cvss 9.9epss 0.02

    NodeBB before version 1.14.3 has a bug introduced in version 1.12.2 in the validation logic that makes it possible to change the password of any user on a running NodeBB forum by sending a specially crafted socket.io call to the server. This could lead to a privilege escalation…

Page 2 of 2