Description
util/FileDownloadUtils.java in FileDownloader 1.7.3 does not check an attachment's name. If an attacker places "../" in the file name, the file can be stored in an unintended directory because of Directory Traversal.
Remediation
References
https://github.com/lingochamp/FileDownloader/issues/1028
Related Vulnerabilities
CVE-2018-5158 Vulnerability in maven package org.webjars.npm:pdfjs-dist
CVE-2020-28449 Vulnerability in npm package decal
CVE-2022-23618 Vulnerability in maven package org.xwiki.platform:xwiki-platform-oldcore
CVE-2022-1243 Vulnerability in npm package urijs
CVE-2018-1000123 Vulnerability in npm package cordova-plugin-ios-keychain