NodeBB Plugin Emoji 3.2.1 contains an arbitrary file write vulnerability that allows administrative users to write files to arbitrary system locations through the emoji upload API. Attackers with admin access can craft file upload requests with directory traversal to overwrite system files by manipulating the file path parameter.
Metrics
Affected Vendors & Products
References
History
Wed, 21 Jan 2026 17:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | NodeBB Plugin Emoji 3.2.1 contains an arbitrary file write vulnerability that allows administrative users to write files to arbitrary system locations through the emoji upload API. Attackers with admin access can craft file upload requests with directory traversal to overwrite system files by manipulating the file path parameter. | |
| Title | NodeBB Plugin Emoji 3.2.1 - Arbitrary File Write | |
| Weaknesses | CWE-73 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-01-21T17:27:31.014Z
Reserved: 2025-12-31T02:09:17.953Z
Link: CVE-2021-47746
No data.
Status : Received
Published: 2026-01-21T18:16:02.687
Modified: 2026-01-21T18:16:02.687
Link: CVE-2021-47746
No data.
OpenCVE Enrichment
No data.