Vulnerabilities (CVE)

Filtered by vendor Dgtl Subscribe
Filtered by product Huemagic
Total 2 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2021-26504 1 Dgtl 1 Huemagic 2024-02-28 N/A 7.5 HIGH
Directory Traversal vulnerability in Foddy node-red-contrib-huemagic version 3.0.0, allows remote attackers to gain sensitive information via crafted request in res.sendFile API in hue-magic.js.
CVE-2021-25864 1 Dgtl 1 Huemagic 2024-02-28 5.0 MEDIUM 7.5 HIGH
node-red-contrib-huemagic 3.0.0 is affected by hue/assets/..%2F Directory Traversal.in the res.sendFile API, used in file hue-magic.js, to fetch an arbitrary file.