{"id":"CVE-2021-43787","details":"Nodebb is an open source Node.js based forum software. In affected versions a prototype pollution vulnerability in the uploader module allowed a malicious user to inject arbitrary data (i.e. javascript) into the DOM, theoretically allowing for an account takeover when used in conjunction with a path traversal vulnerability disclosed at the same time as this report. The vulnerability has been patched as of v1.18.5. Users are advised to upgrade as soon as possible.","aliases":["GHSA-wx69-rvg3-x7fc"],"modified":"2026-07-09T11:24:15.513207Z","published":"2021-11-29T20:15:08.190Z","references":[{"type":"FIX","url":"https://github.com/NodeBB/NodeBB/commit/1783f918bc19568f421473824461ff2ed7755e4c"},{"type":"FIX","url":"https://github.com/NodeBB/NodeBB/releases/tag/v1.18.5"},{"type":"FIX","url":"https://github.com/NodeBB/NodeBB/security/advisories/GHSA-wx69-rvg3-x7fc"},{"type":"EVIDENCE","url":"https://blog.sonarsource.com/nodebb-remote-code-execution-with-one-shot/"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/nodebb/nodebb","events":[{"introduced":"e8ca993aac4b90cfea131050814a19e144a27094"},{"last_affected":"abbbc3d7c2c75a7877ee55debb9f47114e692778"},{"fixed":"1783f918bc19568f421473824461ff2ed7755e4c"},{"fixed":"c28ac8ec52910c4f9fffec5fb11de2705126c790"}],"database_specific":{"extracted_events":[{"introduced":"1.15.5"},{"last_affected":"1.18.4"}],"source":["CPE_RANGE","REFERENCES"],"cpe":"cpe:2.3:a:nodebb:nodebb:*:*:*:*:*:*:*:*"}}],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2021-43787.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"}]}