CVE-2022-25931

All versions of package easy-static-server are vulnerable to Directory Traversal due to missing input sanitization and sandboxes being employed to the req.url user input that is passed to the server code.
Advertisement

NeevaHost hosting service

Configurations

Configuration 1 (hide)

cpe:2.3:a:easy-static-server_project:easy-static-server:*:*:*:*:*:node.js:*:*

Information

Published : 2022-12-19 21:15

Updated : 2022-12-29 10:45


NVD link : CVE-2022-25931

Mitre link : CVE-2022-25931


JSON object : View

CWE
CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

Advertisement

dedicated server usa

Products Affected

easy-static-server_project

  • easy-static-server