We use these services and cookies to improve your user experience. You may opt out if you wish, however, this may limit some features on this site.

Please see our statement on Data Privacy.

Crisp.chat (Helpdesk and Chat)

Ok

THREATINT
PUBLISHED

CVE-2016-10532



Assignerhackerone
Reserved2017-10-29
Published2018-05-31
Updated2024-09-16

Description

console-io is a module that allows users to implement a web console in their application. A malicious user could bypass the authentication and execute any command that the user who is running the console-io application 2.2.13 and earlier is able to run. This means that if console-io was running from root, the attacker would have full access to the system. This vulnerability exists because the console-io application does not configure socket.io to require authentication, which allows a malicious user to connect via a websocket to send commands and receive the response.

Product status

<=2.2.13
affected

References

https://nodesecurity.io/advisories/90

cve.org CVE-2016-10532

nvd.nist.gov CVE-2016-10532

Download JSON

Share this page
https://cve.threatint.com/CVE/CVE-2016-10532
Support options

Helpdesk Telegram

Subscribe to our newsletter to learn more about our work.