Description
mfrserver is a simple file server. mfrserver is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url.
Remediation
References
https://github.com/JacksonGL/NPM-Vuln-PoC/blob/master/directory-traversal/mfrserver
https://nodesecurity.io/advisories/421
Related Vulnerabilities
CVE-2020-12827 Vulnerability in maven package org.webjars.npm:mjml
CVE-2018-3770 Vulnerability in npm package markdown-pdf
CVE-2020-7622 Vulnerability in maven package io.jooby:jooby-netty
CVE-2021-23509 Vulnerability in npm package json-ptr
CVE-2021-42550 Vulnerability in maven package ch.qos.logback:logback-core