Description
chatbyvista is a file server. chatbyvista is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url.
Remediation
References
https://github.com/JacksonGL/NPM-Vuln-PoC/blob/master/directory-traversal/chatbyvista
https://nodesecurity.io/advisories/462
Related Vulnerabilities
CVE-2019-18213 Vulnerability in maven package org.lsp4xml:lsp4xml-extensions
CVE-2021-44868 Vulnerability in maven package net.mingsoft:ms-mcms
CVE-2018-20595 Vulnerability in maven package org.hswebframework.web:hsweb-system-oauth2-client-web
CVE-2020-26291 Vulnerability in npm package urijs
CVE-2022-34114 Vulnerability in maven package io.dataease:dataease-plugin-common