NodeBB Plugin Emoji 3.2.1 contains an arbitrary file write vulnerability that allows administrative users to write files to arbitrary system locations through the emoji upload API. Attackers with admin access can craft file upload requests with directory traversal to overwrite system files by manipulating the file path parameter.
References
Configurations
No configuration.
History
No history.
Information
Published : 2026-01-21 18:16
Updated : 2026-01-26 15:04
NVD link : CVE-2021-47746
Mitre link : CVE-2021-47746
CVE.ORG link : CVE-2021-47746
JSON object : View
Products Affected
No product.
CWE
CWE-73
External Control of File Name or Path
