Executive brief
Saltcorn is an open-source web development platform used to build database applications and mobile apps. An authenticated administrator can exploit an unvalidated parameter in the mobile app build feature to list arbitrary filenames and directory names on the server's filesystem, potentially exposing sensitive naming conventions or structure without being able to read file contents.
Technical details
This is a path traversal and directory listing vulnerability (CWE-548) in the /admin/build-mobile-app/result endpoint. The build_dir_name query parameter is not validated before being used in a path.join() call to construct a directory path, which is then read with readdirSync(). An attacker can supply path traversal sequences (e.g., /../../../../../../../../) to escape the intended mobile_app directory and enumerate files in arbitrary locations. The vulnerability requires admin privileges and allows reading only filenames and directory names, not file contents. The fix validates the build_dir_name parameter format and verifies that the resolved buildDir path starts with the intended root location.
Affected products
- Saltcorn @saltcorn/server <=1.0.0-beta.13
Timeline
- 2024-10-03: disclosed
- 2024-10-03: patched: Fixed in version 1.0.0-beta.14