0.55.8
5 years ago
1 months ago
Known vulnerabilities in the changedetection.io package. This does not include vulnerabilities belonging to this package’s dependencies.
Snyk's AI Trust Platform automatically finds the best upgrade path and integrates with your development workflows. Secure your code at zero cost.
Fix for free| Vulnerability | Vulnerable Version |
|---|---|
changedetection.io is a Website change detection and monitoring service Affected versions of this package are vulnerable to XML External Entity (XXE) Injection via the How to fix XML External Entity (XXE) Injection? Upgrade | [,0.55.1) |
changedetection.io is a Website change detection and monitoring service Affected versions of this package are vulnerable to External Control of File Name or Path through the backup restoration. An attacker can access arbitrary local files by supplying a crafted backup archive containing a manipulated How to fix External Control of File Name or Path? Upgrade | [,0.55.1) |
changedetection.io is a Website change detection and monitoring service Affected versions of this package are vulnerable to Incorrect Authorization due to improper decorator ordering in route registration. An attacker can gain unauthorized access to sensitive backup files, exfiltrate confidential configuration data, trigger backup creation or deletion, and potentially inject malicious configurations by sending unauthenticated requests to specific endpoints. How to fix Incorrect Authorization? Upgrade | [,0.54.8) |
changedetection.io is a Website change detection and monitoring service Affected versions of this package are vulnerable to Incomplete List of Disallowed Inputs via the How to fix Incomplete List of Disallowed Inputs? Upgrade | [,0.54.7) |
changedetection.io is a Website change detection and monitoring service Affected versions of this package are vulnerable to Information Exposure via the Note: This is only exploitable if authentication is not enabled or if the attacker has valid credentials. How to fix Information Exposure? Upgrade | [,0.54.7) |
changedetection.io is a Website change detection and monitoring service Affected versions of this package are vulnerable to Directory Traversal via the How to fix Directory Traversal? Upgrade | [,0.54.4) |
changedetection.io is a Website change detection and monitoring service Affected versions of this package are vulnerable to Arbitrary Code Injection via the How to fix Arbitrary Code Injection? Upgrade | [,0.54.4) |
changedetection.io is a Website change detection and monitoring service Affected versions of this package are vulnerable to Cross-site Scripting (XSS) via the Note: This is only exploitable if the attacker obtains a valid RSS access token, which can be extracted from the homepage How to fix Cross-site Scripting (XSS)? Upgrade | [,0.54.4) |
changedetection.io is a Website change detection and monitoring service Affected versions of this package are vulnerable to Server-side Request Forgery (SSRF) via the Note: This is only exploitable if no password is configured for the application, which is the default setting. How to fix Server-side Request Forgery (SSRF)? Upgrade | [,0.54.1) |
changedetection.io is a Website change detection and monitoring service Affected versions of this package are vulnerable to Cross-site Scripting (XSS) via the How to fix Cross-site Scripting (XSS)? Upgrade | [,0.54.1) |
changedetection.io is a Website change detection and monitoring service Affected versions of this package are vulnerable to Directory Traversal via the How to fix Directory Traversal? Upgrade | [,0.53.2) |
changedetection.io is a Website change detection and monitoring service Affected versions of this package are vulnerable to Cross-site Scripting (XSS) via the How to fix Cross-site Scripting (XSS)? Upgrade | [,0.50.34) |
changedetection.io is a Website change detection and monitoring service Affected versions of this package are vulnerable to Cross-site Scripting (XSS) via improper handling of errors in How to fix Cross-site Scripting (XSS)? Upgrade | [,0.50.4) |
changedetection.io is a Website change detection and monitoring service Affected versions of this package are vulnerable to Directory Traversal on URLs received as input. An attacker can read local files via the watch preview functionality. URLs are not sufficiently checked for paths that traverse directories with a "dot-dot" pattern, paths beginning with a space. How to fix Directory Traversal? Upgrade | [,0.48.5) |
changedetection.io is a Website change detection and monitoring service Affected versions of this package are vulnerable to Directory Traversal due to improper validation for the file Note:
This issue only affects instances with a How to fix Directory Traversal? Upgrade | [,0.47.6) |
changedetection.io is a Website change detection and monitoring service Affected versions of this package are vulnerable to Directory Traversal via the How to fix Directory Traversal? Upgrade | [,0.47.5) |
changedetection.io is a Website change detection and monitoring service Affected versions of this package are vulnerable to Cross-site Scripting (XSS) due to improper sanitization of user input in the How to fix Cross-site Scripting (XSS)? Upgrade | [,0.45.22) |