0.50.39
4 years ago
9 hours ago
Known vulnerabilities in the changedetection.io package. This does not include vulnerabilities belonging to this package’s dependencies.
Snyk's AI Trust Platform automatically finds the best upgrade path and integrates with your development workflows. Secure your code at zero cost.
Fix for free| Vulnerability | Vulnerable Version | 
|---|---|
 changedetection.io is a Website change detection and monitoring service Affected versions of this package are vulnerable to Cross-site Scripting (XSS) via improper handling of errors in  How to fix Cross-site Scripting (XSS)? Upgrade   | [,0.50.4)  | 
 changedetection.io is a Website change detection and monitoring service Affected versions of this package are vulnerable to Directory Traversal on URLs received as input. An attacker can read local files via the watch preview functionality. URLs are not sufficiently checked for paths that traverse directories with a "dot-dot" pattern, paths beginning with a space. How to fix Directory Traversal? Upgrade   | [,0.48.5)  | 
 changedetection.io is a Website change detection and monitoring service Affected versions of this package are vulnerable to Directory Traversal due to improper validation for the file  Note:
This issue only affects instances with a  How to fix Directory Traversal? Upgrade   | [,0.47.6)  | 
 changedetection.io is a Website change detection and monitoring service Affected versions of this package are vulnerable to Directory Traversal via the  How to fix Directory Traversal? Upgrade   | [,0.47.5)  | 
 changedetection.io is a Website change detection and monitoring service Affected versions of this package are vulnerable to Cross-site Scripting (XSS) due to improper sanitization of user input in the  How to fix Cross-site Scripting (XSS)? Upgrade   | [,0.45.22)  |