Description
citypredict.whauwiller is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url.
Remediation
References
https://github.com/JacksonGL/NPM-Vuln-PoC/tree/master/directory-traversal/citypredict.whauwiller
https://nodesecurity.io/advisories/370
Related Vulnerabilities
CVE-2021-26707 Vulnerability in maven package org.webjars.npm:merge-deep
CVE-2017-16094 Vulnerability in npm package iter-http
CVE-2018-9206 Vulnerability in maven package org.webjars.npm:blueimp-file-upload
CVE-2021-32673 Vulnerability in npm package reg-keygen-git-hash-plugin
CVE-2021-3223 Vulnerability in npm package node-red-dashboard