Description
wintiwebdev is a static file server. wintiwebdev is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url.
Remediation
References
https://github.com/JacksonGL/NPM-Vuln-PoC/blob/master/directory-traversal/wintiwebdev
https://nodesecurity.io/advisories/458
Related Vulnerabilities
CVE-2022-24759 Vulnerability in npm package @chainsafe/libp2p-noise
CVE-2022-23496 Vulnerability in maven package nl.basjes.parse.useragent:yauaa-parent
CVE-2022-2064 Vulnerability in npm package nocodb
CVE-2023-49381 Vulnerability in maven package com.jfinal:jfinal
CVE-2022-25312 Vulnerability in maven package org.apache.any23:apache-any23