GrandNode 4.40 is susceptible to local file inclusion in Controllers/LetsEncryptController.cs, which allows remote unauthenticated attackers to retrieve arbitrary files on the web server via specially crafted LetsEncrypt/Index?fileName= HTTP requests.
View the template here CVE-2019-12276.yaml
References:
https://nvd.nist.gov/vuln/detail/CVE-2019-12276