Description
wffserve is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url.
Remediation
References
https://github.com/JacksonGL/NPM-Vuln-PoC/blob/master/directory-traversal/wffserve
https://nodesecurity.io/advisories/407
Related Vulnerabilities
CVE-2021-21626 Vulnerability in maven package io.jenkins.plugins:warnings-ng
CVE-2021-23341 Vulnerability in npm package prismjs
CVE-2020-7787 Vulnerability in npm package react-adal
CVE-2020-8203 Vulnerability in maven package org.webjars:lodash
CVE-2023-29212 Vulnerability in maven package org.xwiki.platform:xwiki-platform-panels-ui