PT-2022-17591 · Unknown · Lite-Dev-Server

Liran Tal

+1

·

Published

2022-12-21

·

Updated

2023-01-03

·

CVE-2022-25895

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions lite-dev-server versions all
Description The issue arises due to missing input sanitization and the employment of sandboxes to the req.url user input that is passed to the server code, leading to Directory Traversal.
Recommendations For all versions, consider disabling the vulnerable functionality related to the req.url input until a proper fix is available, and ensure proper input sanitization for the req.url variable to prevent Directory Traversal attacks.

Exploit

Fix

Path traversal

Weakness Enumeration

Related Identifiers

CVE-2022-25895
GHSA-PPPV-CH8P-RP2W

Affected Products

Lite-Dev-Server