Description
index.js in Total.js Platform before 3.2.3 allows path traversal.
Remediation
References
https://blog.certimetergroup.com/it/articolo/security/total.js-directory-traversal-cve-2019-8903
https://github.com/totaljs/framework/commit/c37cafbf3e379a98db71c1125533d1e8d5b5aef7
https://github.com/totaljs/framework/commit/de16238d13848149f5d1dae51f54e397a525932b
Related Vulnerabilities
CVE-2023-1108 Vulnerability in maven package io.undertow:undertow-core
CVE-2023-40572 Vulnerability in maven package org.xwiki.platform:xwiki-platform-oldcore
CVE-2022-39353 Vulnerability in maven package org.webjars.npm:xmldom__xmldom
CVE-2020-36649 Vulnerability in maven package org.webjars.npm:papaparse
CVE-2020-17150 Vulnerability in npm package typescript-tslint-plugin