CVE-2023-46496: Path Traversal
Published Dec 8, 2023
·Updated
Directory Traversal vulnerability in EverShop NPM versions before v.1.0.0-rc.8 allows a remote attacker to obtain sensitive information via a crafted request to the DELETE function in api/files endpoint.
Affected Software
13 affected componentsFixes available
npm/@evershop/evershop<1.0.0-rc.8
1.0.0-rc.8
evershop Evershop Node.js=1.0.0-beta
evershop Evershop Node.js=1.0.0-beta1
evershop Evershop Node.js=1.0.0-beta2
evershop Evershop Node.js=1.0.0-beta3
evershop Evershop Node.js=1.0.0-beta4
evershop Evershop Node.js=1.0.0-beta5
evershop Evershop Node.js=1.0.0-rc1
evershop Evershop Node.js=1.0.0-rc2
evershop Evershop Node.js=1.0.0-rc3
evershop Evershop Node.js=1.0.0-rc5
evershop Evershop Node.js=1.0.0-rc6
evershop Evershop Node.js=1.0.0-rc7
Event History
Dec 8, 2023
CVE Published
12:00 AM
Data Sourced
12:00 AM
Description
Advisory Published
09:30 PM
Frequently Asked Questions
1
What is the severity of CVE-2023-46496?
CVE-2023-46496 is considered a medium severity vulnerability due to its ability to expose sensitive information.
2
How do I fix CVE-2023-46496?
To fix CVE-2023-46496, update EverShop NPM to version 1.0.0-rc.8 or later.
3
Which versions of EverShop are affected by CVE-2023-46496?
CVE-2023-46496 affects all EverShop NPM versions prior to v.1.0.0-rc.8.
4
What type of vulnerability is CVE-2023-46496?
CVE-2023-46496 is categorized as a Directory Traversal vulnerability.
5
Can CVE-2023-46496 be exploited remotely?
Yes, CVE-2023-46496 can be exploited remotely via crafted requests to the DELETE function in the api/files endpoint.