Description
citypredict.whauwiller is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url.
Remediation
References
https://github.com/JacksonGL/NPM-Vuln-PoC/tree/master/directory-traversal/citypredict.whauwiller
https://nodesecurity.io/advisories/370
Related Vulnerabilities
CVE-2020-8124 Vulnerability in maven package org.webjars.npm:url-parse
CVE-2020-5259 Vulnerability in maven package org.webjars.bowergithub.dojo:dojox
CVE-2023-26476 Vulnerability in maven package org.xwiki.platform:xwiki-platform-livetable-ui
CVE-2022-0087 Vulnerability in npm package @keystone-6/auth
CVE-2021-21290 Vulnerability in maven package io.netty:netty-testsuite