Description
welcomyzt is a simple file server. welcomyzt is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url.
Remediation
References
https://github.com/JacksonGL/NPM-Vuln-PoC/blob/master/directory-traversal/pooledwebsocket
https://nodesecurity.io/advisories/388
Related Vulnerabilities
CVE-2022-31367 Vulnerability in npm package strapi-plugin-content-type-builder
CVE-2016-4055 Vulnerability in maven package org.webjars.npm:moment
CVE-2021-21626 Vulnerability in maven package io.jenkins.plugins:warnings-ng
CVE-2020-7737 Vulnerability in npm package safetydance
CVE-2021-42697 Vulnerability in maven package com.typesafe.akka:akka-http_2.12