Description
index.js in Total.js Platform before 3.2.3 allows path traversal.
Remediation
References
https://blog.certimetergroup.com/it/articolo/security/total.js-directory-traversal-cve-2019-8903
https://github.com/totaljs/framework/commit/c37cafbf3e379a98db71c1125533d1e8d5b5aef7
https://github.com/totaljs/framework/commit/de16238d13848149f5d1dae51f54e397a525932b
Related Vulnerabilities
CVE-2020-28269 Vulnerability in npm package field
CVE-2023-0868 Vulnerability in maven package org.opennms:opennms-webapp
CVE-2022-36095 Vulnerability in maven package org.xwiki.platform:xwiki-platform-web-templates
CVE-2022-22984 Vulnerability in npm package snyk
CVE-2022-23496 Vulnerability in maven package nl.basjes.parse.useragent:yauaa