Description
The web application exposes Node.js Inspector port. It's not recommended to have Node.js Inspector service publicly accessible as the debugger has full access to the Node.js execution environment and an attacker may be able to execute arbitrary javascript code.
Remediation
Disable Inspector or restrict access to it
References
Related Vulnerabilities
npm log file publicly accessible (npm-debug.log)
PostgreSQL Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2017-7486)
Moodle Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2019-3810)
WordPress Plugin Simple Download Monitor Multiple Vulnerabilities (3.9.5.1)
WordPress Plugin Count per Day Information Disclosure (3.2.5)