Description
An issue in EverShop NPM versions before v.1.0.0-rc.8 allows a remote attacker to obtain sensitive information and execute arbitrary code via the /deleteCustomer/route.json file.
Remediation
References
https://devhub.checkmarx.com/cve-details/Cx8b24ace3-0c9a/
https://devhub.checkmarx.com/cve-details/cve-2023-46498/
Related Vulnerabilities
CVE-2020-7640 Vulnerability in npm package pixl-class
CVE-2021-26707 Vulnerability in npm package merge-deep
CVE-2022-28820 Vulnerability in maven package com.adobe.acs:acs-aem-commons
CVE-2019-10283 Vulnerability in maven package com.mabl.integration.jenkins:mabl-integration
CVE-2016-4431 Vulnerability in maven package org.apache.struts:struts2-core