Security
Headlines
HeadlinesLatestCVEs

Headline

GHSA-4wrm-qmq2-5fjx: Directory Traversal in evershop

Directory Traversal vulnerability in EverShop NPM versions before v.1.0.0-rc.8 allows a remote attacker to obtain sensitive information via a crafted request to the readDirSync function in fileBrowser/browser.js.

ghsa
#vulnerability#nodejs#js#git

Directory Traversal in evershop

Moderate severity GitHub Reviewed Published Dec 8, 2023 to the GitHub Advisory Database • Updated Dec 13, 2023

Related news

CVE-2023-46493: Relative Path Traversal in @evershop/evershop - Cxa4d94170-be41 - DevHub

Directory Traversal vulnerability in EverShop NPM versions before v.1.0.0-rc.8 allows a remote attacker to obtain sensitive information via a crafted request to the readDirSync function in fileBrowser/browser.js.