Critical LFI Vulnerability Reported in Hashnode Blogging PlatformThe Hacker News

Torna a Articoli

Critical LFI Vulnerability Reported in Hashnode Blogging PlatformThe Hacker News

Researchers have disclosed a previously undocumented local file inclusion (LFI) vulnerability in Hashnode, a developer-oriented blogging platform, that could be abused to access sensitive data such as SSH keys, server’s IP address, and other network information.
“The LFI originates in a Bulk Markdown Import feature that can be manipulated to provide attackers with unimpeded ability to downloadRead More

Condividi questo post

Torna a Articoli