Description
index.js in Total.js Platform before 3.2.3 allows path traversal.
Remediation
References
https://blog.certimetergroup.com/it/articolo/security/total.js-directory-traversal-cve-2019-8903
https://github.com/totaljs/framework/commit/c37cafbf3e379a98db71c1125533d1e8d5b5aef7
https://github.com/totaljs/framework/commit/de16238d13848149f5d1dae51f54e397a525932b
Related Vulnerabilities
CVE-2020-26299 Vulnerability in npm package ftp-srv
CVE-2022-2596 Vulnerability in npm package node-fetch
CVE-2021-23900 Vulnerability in maven package com.mikesamuel:json-sanitizer
CVE-2023-32069 Vulnerability in maven package org.xwiki.platform:xwiki-platform-xclass-ui
CVE-2020-35460 Vulnerability in maven package net.sf.mpxj:mpxj