Description
Directory Traversal vulnerability in EverShop NPM versions before v.1.0.0-rc.8 allows a remote attacker to obtain sensitive information via a crafted request to the DELETE function in api/files endpoint.
Remediation
References
https://devhub.checkmarx.com/cve-details/CVE-2023-46496/
https://devhub.checkmarx.com/cve-details/Cx943be66a-54cc/
Related Vulnerabilities
CVE-2020-2292 Vulnerability in maven package org.jenkins-ci.plugins:release
CVE-2016-10529 Vulnerability in npm package droppy
CVE-2016-10735 Vulnerability in maven package org.ow2.jonas:bootstrap
CVE-2018-3784 Vulnerability in npm package cryo
CVE-2023-36479 Vulnerability in maven package org.eclipse.jetty:jetty-servlets