ZeroHour
Exploit-DBpublished ()ingested

[webapps] Nodemailer 9.0.0 - File Read/ SSRF

mediumExploit / PoCimportance 35
AI summary · glm-5.3-flash

A public proof-of-concept demonstrates arbitrary file read and SSRF in Nodemailer 9.0.0.

Exploit-DB entry 52654 contains a webapps proof-of-concept for Nodemailer 9.0.0 demonstrating both arbitrary file read and server-side request forgery. Nodemailer is a widely used Node.js email-sending library, so affected deployments could expose local files or internal services. The listing does not include a CVE identifier or evidence of in-the-wild exploitation.

  • File-read and SSRF PoC published for Nodemailer 9.0.0
  • Nodemailer is a widely deployed Node.js email library
Full article

Nodemailer 9.0.0 - File Read/ SSRF

This source does not provide full text. Read it at exploit-db.com.