CVE-2023-46498: Critical severity evershop Evershop Node.js vulnerability
An issue in EverShop NPM versions before v.1.0.0-rc.8 allows a remote attacker to obtain sensitive information and execute arbitrary code via the /deleteCustomer/route.json file.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-46498?
CVE-2023-46498 is a critical vulnerability that allows remote attackers to obtain sensitive information and execute arbitrary code.
How do I fix CVE-2023-46498?
To fix CVE-2023-46498, upgrade to EverShop NPM version 1.0.0-rc.8 or later.
What versions of EverShop are affected by CVE-2023-46498?
CVE-2023-46498 affects EverShop NPM versions prior to v.1.0.0-rc.8, including all beta and release candidate versions before this.
What type of attack does CVE-2023-46498 enable?
CVE-2023-46498 enables remote attackers to execute arbitrary code on the affected systems.
Is CVE-2023-46498 considered a remote code execution vulnerability?
Yes, CVE-2023-46498 is categorized as a remote code execution vulnerability due to its ability to allow arbitrary code execution from a remote attacker.