Vulnerabilities/

Etherpad Lite Access Restriction Bypass

Severity:
High

Description

node/hooks/express/apicalls.js in Etherpad Lite before v1.6.3 mishandles JSONP, which allows remote attackers to bypass intended access restrictions.

Recommendation

Update the ep_etherpad-lite package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
ep_etherpad-lite
Anything's wrong? Let us know Last updated on October 06, 2023

This issue is available in SmartScanner Professional

See Pricing