@saltcorn/server
Server app for Saltcorn, open-source no-code platform
High Security Advisories for @saltcorn/server in npm Clear Filters
High
4 months ago
Saltcorn has an Unauthenticated Path Traversal in sync endpoints, allowing arbitrary file write and directory read
npm
@saltcorn/server
High
almost 2 years ago
Saltcorn Server allows logged-in users to delete arbitrary files because of a path traversal vulnerability
npm
@saltcorn/server
Potential
High
almost 2 years ago
@saltcorn/plugins-loader unsanitized plugin name leads to a remote code execution (RCE) vulnerability when creating plugins using git source
npm
@saltcorn/plugins-loader
High
almost 2 years ago
@saltcorn/server Remote Code Execution (RCE) / SQL injection via prototype pollution by manipulating `lang` and `defstring` parameters when setting localizer strings
npm
@saltcorn/server
Potential
High
about 3 years ago
Unsafe plugins can be installed via pack import by tenant admins
npm
@saltcorn/cli