Vulnerabilities
Vulnerable Software
Sailsjs:  >> Sails  >> 0.12.11-1  Security Vulnerabilities
Sails is a realtime MVC Framework for Node.js. In Sails apps prior to version 1.5.7,, an attacker can send a virtual request that will cause the node process to crash. This behavior was fixed in Sails v1.5.7. As a workaround, disable the sockets hook and remove the `sails.io.js` client.
CVSS Score
7.5
EPSS Score
0.002
Published
2023-07-27
SailsJS Sails.js <=1.4.0 is vulnerable to Prototype Pollution via controller/load-action-modules.js, function loadActionModules().
CVSS Score
9.8
EPSS Score
0.004
Published
2022-03-17
Sails.js before v1.0.0-46 allows attackers to cause a denial of service with a single request because there is no error handler in sails-hook-sockets to handle an empty pathname in a WebSocket request.
CVSS Score
7.5
EPSS Score
0.007
Published
2020-07-21


Contact Us

Shodan ® - All rights reserved