Vulnerabilities > Socket IO File Project

DATE CVE VULNERABILITY TITLE RISK
2020-10-06 CVE-2020-24807 Improper Input Validation vulnerability in Socket.Io-File Project Socket.Io-File
The socket.io-file package through 2.0.31 for Node.js relies on client-side validation of file types, which allows remote attackers to execute arbitrary code by uploading an executable file via a modified JSON name field.
local
low complexity
socket-io-file-project CWE-20
7.8
2020-07-15 CVE-2020-15779 Path Traversal vulnerability in Socket.Io-File Project Socket.Io-File
A Path Traversal issue was discovered in the socket.io-file package through 2.0.31 for Node.js.
network
low complexity
socket-io-file-project CWE-22
7.5