.. / CVE-2021-3223

Exploit for Node RED Dashboard <2.26.2 - Local File Inclusion (CVE-2021-3223)

Description:

NodeRED-Dashboard before 2.26.2 is vulnerable to local file inclusion because it allows ui_base/js/..%2f directory traversal to read files.

Nuclei Template

View the template here CVE-2021-3223.yaml

Validate with Nuclei

echo "$URL" | nuclei -t ~/nuclei-templates/http/cves/2021/CVE-2021-3223.yaml
Copy

References:

https://github.com/node-red/node-red-dashboard/releases/tag/2.26.2
https://github.com/ARPSyndicate/cvemon
https://nvd.nist.gov/vuln/detail/CVE-2021-3223
https://github.com/node-red/node-red-dashboard/issues/669
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-3223