Executive brief
EverShop is a Node.js e-commerce platform that allows businesses to build online stores. A directory traversal vulnerability in the file deletion API endpoint allows authenticated attackers to read, modify, or delete arbitrary files on the server, potentially exposing sensitive customer data, order information, or enabling complete system compromise.
Technical details
A directory traversal (CWE-22) vulnerability exists in the DELETE function of the /api/files endpoint in EverShop versions before 1.0.0-rc.8. The vulnerability allows authenticated attackers to craft requests using path traversal sequences (e.g., "../") to access and delete files outside the intended directory. Authentication is required but the vulnerability requires no user interaction. An attacker with valid credentials can enumerate the filesystem, exfiltrate sensitive files, or delete critical application data. The issue was patched in version 1.0.0-rc.8 (merged September 2023).
Affected products
- EverShop EverShop before 1.0.0-rc.8
Timeline
- 2023-12-08: disclosed
- 2023-09-27: patched: Fix merged in PR #338