Vulnerabilities
Vulnerable Software
Serve-Lite Project:  >> Serve-Lite  Security Vulnerabilities
All versions of the package serve-lite are vulnerable to Cross-site Scripting (XSS) because when it detects a request to a directory, it renders a file listing of all of its contents with links that include the actual file names without any sanitization or output encoding.
CVSS Score
5.4
EPSS Score
0.003
Published
2023-01-26
All versions of the package serve-lite are vulnerable to Directory Traversal due to missing input sanitization or other checks and protections employed to the req.url passed as-is to path.join().
CVSS Score
7.5
EPSS Score
0.011
Published
2023-01-26


Contact Us

Shodan ® - All rights reserved