Description
whispercast is a file server. whispercast is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url.
Remediation
References
https://nodesecurity.io/advisories/466
https://github.com/JacksonGL/NPM-Vuln-PoC/blob/master/directory-traversal/whispercast
Related Vulnerabilities
CVE-2016-15011 Vulnerability in maven package be.e_contract.dssp:dssp-client
CVE-2020-36189 Vulnerability in maven package com.fasterxml.jackson.core:jackson-databind
CVE-2022-39313 Vulnerability in npm package parse-server
CVE-2017-11555 Vulnerability in maven package org.webjars.npm:node-sass
CVE-2018-10237 Vulnerability in maven package com.google.guava:guava