Headline
GHSA-rwf3-w4jq-f4cm: Directory Traversal in evershop
Directory Traversal vulnerability in EverShop NPM versions before v.1.0.0-rc.8 allows a remote attacker to obtain sensitive information via a crafted request to the DELETE function in api/files endpoint.
Directory Traversal in evershop
High severity GitHub Reviewed Published Dec 8, 2023 to the GitHub Advisory Database • Updated Dec 13, 2023
Related news
CVE-2023-46496: Relative Path Traversal in @evershop/evershop - Cx943be66a-54cc - DevHub
Directory Traversal vulnerability in EverShop NPM versions before v.1.0.0-rc.8 allows a remote attacker to obtain sensitive information via a crafted request to the DELETE function in api/files endpoint.