Description
scott-blanch-weather-app is a sample Node.js app using Express 4. scott-blanch-weather-app is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url.
Remediation
References
https://github.com/JacksonGL/NPM-Vuln-PoC/blob/master/directory-traversal/scott-blanch-weather-app
https://nodesecurity.io/advisories/453
Related Vulnerabilities
CVE-2019-10793 Vulnerability in maven package org.webjars.bower:dot-object
CVE-2020-6461 Vulnerability in npm package electron
CVE-2021-23342 Vulnerability in maven package org.webjars.npm:docsify
CVE-2021-46708 Vulnerability in maven package org.webjars.npm:swagger-ui-dist
CVE-2022-26049 Vulnerability in maven package com.diffplug.gradle:goomph