GrandNode 4.40 is susceptible to local file inclusion in Controllers/LetsEncryptController.cs, which allows remote unauthenticated attackers to retrieve arbitrary files on the web server via specially crafted LetsEncrypt/Index?fileName= HTTP requests.
id: CVE-2019-12276
info:
name: GrandNode 4.40 - Local File Inclusion
author: daffainfo
severi
...