Description
An issue in EverShop NPM versions before v.1.0.0-rc.8 allows a remote attacker to obtain sensitive information and execute arbitrary code via the /deleteCustomer/route.json file.
Remediation
References
https://devhub.checkmarx.com/cve-details/cve-2023-46498/
https://devhub.checkmarx.com/cve-details/Cx8b24ace3-0c9a/
Related Vulnerabilities
CVE-2018-1000665 Vulnerability in maven package org.dojotoolkit:dojo
CVE-2016-10547 Vulnerability in maven package org.webjars.npm:nunjucks
CVE-2015-3250 Vulnerability in maven package org.apache.directory.api:api-ldap-client-all
CVE-2019-10410 Vulnerability in maven package org.jenkins-ci.plugins:log-parser
CVE-2019-1003089 Vulnerability in maven package ren.helloworld:upload-pgyer