Description
dylmomo is a simple file server. dylmomo is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url.
Remediation
References
https://github.com/JacksonGL/NPM-Vuln-PoC/blob/master/directory-traversal/dylmomo
https://nodesecurity.io/advisories/396
Related Vulnerabilities
CVE-2020-35490 Vulnerability in maven package com.fasterxml.jackson.core:jackson-databind
CVE-2023-24187 Vulnerability in maven package com.bstek.ureport:ureport2-core
CVE-2023-47320 Vulnerability in maven package org.silverpeas.core:silverpeas-core-web
CVE-2020-28479 Vulnerability in maven package org.webjars.npm:jointjs
CVE-2023-45648 Vulnerability in maven package org.apache.tomcat:tomcat