Description
The web application exposes Node.js Debugger port. It's not recommended to have Node.js Debugger service publicly accessible as the debugger has full access to the Node.js execution environment and an attacker may be able to execute arbitrary javascript code.
Remediation
Disable Debugger or restrict access to it
References
Related Vulnerabilities
XML external entity injection via File Upload
Subresource Integrity (SRI) Not Implemented
WordPress Plugin WordPress Mobile Pack Information Disclosure (2.1.2)
Moodle Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2013-1831)
Moodle Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2016-0724)