DescriptionDirectory traversal vulnerability in node/utils/Minify.js in Etherpad 1.1.1 through 1.5.2 allows remote attackers to read arbitrary files by leveraging replacement of backslashes with slashes in the path parameter of HTTP API requests.
Overall state of this security issue: Does not affect SUSE products
This issue is currently rated as having moderate severity.
|National Vulnerability Database
SUSE Timeline for this CVECVE page created: Sun Apr 12 21:41:53 2015
CVE page last modified: Fri Oct 7 12:47:08 2022