Description
ZEIT Next.js 4 before 4.2.3 has Directory Traversal under the /_next request namespace.
Remediation
References
Related Vulnerabilities
Drupal Unrestricted Upload of File with Dangerous Type Vulnerability (CVE-2017-6931)
ownCloud Improper Restriction of XML External Entity Reference Vulnerability (CVE-2014-2052)
WordPress Plugin WP-Polls SQL Injection (2.71)
WordPress Plugin WordPress File Upload Cross-Site Scripting (4.3.3)
Atlassian Jira Incorrect Default Permissions Vulnerability (CVE-2019-20106)