index.js in Total.js Platform before 3.2.3 allows path traversal.
The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.
Link | Tags |
---|---|
https://github.com/totaljs/framework/commit/c37cafbf3e379a98db71c1125533d1e8d5b5aef7 | third party advisory patch |
https://github.com/totaljs/framework/commit/de16238d13848149f5d1dae51f54e397a525932b | third party advisory patch |
https://blog.certimetergroup.com/it/articolo/security/total.js-directory-traversal-cve-2019-8903 |