CVE-2023-46497: Path Traversal
Directory Traversal vulnerability in EverShop NPM versions before v.1.0.0-rc.8 allows a remote attacker to obtain sensitive information via a crafted request to the mkdirSync function in the folderCreate/createFolder.js endpoint.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-46497?
CVE-2023-46497 has been classified as a moderate severity vulnerability due to its potential to expose sensitive information.
How do I fix CVE-2023-46497?
To fix CVE-2023-46497, update the EverShop NPM package to version 1.0.0-rc.8 or later.
What impact does CVE-2023-46497 have on affected systems?
CVE-2023-46497 allows remote attackers to gain unauthorized access to sensitive information through directory traversal.
Which versions of EverShop are affected by CVE-2023-46497?
CVE-2023-46497 affects all EverShop NPM versions prior to 1.0.0-rc.8.
Is there a way to detect CVE-2023-46497 on my system?
You can detect CVE-2023-46497 by scanning your project for the version of EverShop NPM being used and checking if it is below 1.0.0-rc.8.