Описание
MJML allows mj-include directory traversal due to an incomplete fix for CVE-2020-12827
MJML through 4.18.0 allows mj-include directory traversal to test file existence and (in the type="css" case) read files. NOTE: this issue exists because of an incomplete fix for CVE-2020-12827.
Пакеты
Наименование
mjml
npm
Затронутые версииВерсия исправления
<= 4.18.0
Отсутствует
Связанные уязвимости
CVSS3: 4.5
nvd
около 2 месяцев назад
MJML through 4.18.0 allows mj-include directory traversal to test file existence and (in the type="css" case) read files. NOTE: this issue exists because of an incomplete fix for CVE-2020-12827.