CVE-2021-47746

NodeBB Plugin Emoji 3.2.1 contains an arbitrary file write vulnerability that allows administrative users to write files to arbitrary system locations through the emoji upload API. Attackers with admin access can craft file upload requests with directory traversal to overwrite system files by manipulating the file path parameter.
Configurations

No configuration.

History

No history.

Information

Published : 2026-01-21 18:16

Updated : 2026-01-26 15:04


NVD link : CVE-2021-47746

Mitre link : CVE-2021-47746

CVE.ORG link : CVE-2021-47746


JSON object : View

Products Affected

No product.

CWE
CWE-73

External Control of File Name or Path