adapt-security / adapt-authoring

A server-based user interface for authoring eLearning courses using the Adapt framework.
http://adaptlearning.org
10 stars 5 forks source link

Need to sanitise name value before performing fs read #544

Closed taylortom closed 1 year ago

taylortom commented 1 year ago

REPORTED BY SNYK

https://github.com/adapt-security/adapt-authoring-contentplugin/blob/master/lib/ContentPluginModule.js#L311-L312

See: https://owasp.org/www-community/attacks/Path_Traversal

taylortom commented 1 year ago

Moved to https://github.com/adapt-security/adapt-authoring/issues/584