CVE-2022-25936

Versions of the package servst before 2.0.3 are vulnerable to Directory Traversal due to improper sanitization of the filePath variable.
Configurations

Configuration 1 (hide)

cpe:2.3:a:servst_project:servst:*:*:*:*:*:node.js:*:*

History

21 Nov 2024, 06:53

Type Values Removed Values Added
Summary
  • (es) Las versiones del paquete servst anteriores a la 2.0.3 son vulnerables a Directory Traversal debido a una sanitización inadecuada de la variable filePath.
References () https://gist.github.com/lirantal/691d02d607753d54856f9335f9a1692f - Exploit, Third Party Advisory () https://gist.github.com/lirantal/691d02d607753d54856f9335f9a1692f - Exploit, Third Party Advisory
References () https://github.com/andrepolischuk/servst/commit/f7cae5d2d7c64c86bc512e1e50614240396ef114 - Patch, Third Party Advisory () https://github.com/andrepolischuk/servst/commit/f7cae5d2d7c64c86bc512e1e50614240396ef114 - Patch, Third Party Advisory
References () https://security.snyk.io/vuln/SNYK-JS-SERVST-3244896 - Exploit, Third Party Advisory () https://security.snyk.io/vuln/SNYK-JS-SERVST-3244896 - Exploit, Third Party Advisory

Information

Published : 2023-01-30 05:15

Updated : 2025-03-27 21:15


NVD link : CVE-2022-25936

Mitre link : CVE-2022-25936

CVE.ORG link : CVE-2022-25936


JSON object : View

Products Affected

servst_project

  • servst
CWE
CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')