Low CVSS 3.8

Overview

LiquidFiles before 4.1.2 allows directory traversal by configuring the pathname of a local executable file as an Actionscript.

Risk analysis

This vulnerability is rated 🟢 LOW.

  • CVSS: 3.8 (LOW)
  • Detected tags: path (tag impact: MODERATE)

Recommended actions:

  • Canonicalize path; block `..` traversal; use allowlists.

Recommended tools

Tags