Vulnerabilities/

Path Traversal in crud-file-server

Severity:
High

Description

Versions of crud-file-server prior to 0.9.0 are vulnerable to Path Traversal. The package fails to sanitize URLs, allowing attackers to access server files outside of the served folder using relative paths.

Recommendation

Update the crud-file-server package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
crud-file-server
Anything's wrong? Let us know Last updated on March 01, 2023

This issue is available in SmartScanner Professional

See Pricing