External Control of File Name or Path in GitHub repository flatpressblog/flatpress prior to 1.3.
The product allows user input to control or influence paths or file names that are used in filesystem operations.
Link | Tags |
---|---|
https://github.com/flatpressblog/flatpress/commit/5d5c7f6d8f072d14926fc2c3a97cdd763802f170 | patch |
https://huntr.dev/bounties/4089a63f-cffd-42f3-b8d8-e80b6bd9c80f | issue tracking patch exploit third party advisory |