Description
The PharStreamWrapper (aka phar-stream-wrapper) package 2.x before 2.1.1 and 3.x before 3.1.1 for TYPO3 does not prevent directory traversal, which allows attackers to bypass a deserialization protection mechanism, as demonstrated by a phar:///path/bad.phar/../good.phar URL.
Remediation
References
Related Vulnerabilities
WordPress Plugin Easy Contact Forms Export 'file' Parameter Information Disclosure (1.1.0)
Skipper Server-Side Request Forgery (SSRF) Vulnerability (CVE-2022-38580)
WordPress 5.3.x Prototype Pollution (5.3 - 5.3.11)
WebLogic CVE-2017-10147 Vulnerability (CVE-2017-10147)
WordPress Plugin 360 Product Viewer Cross-Site Scripting (2.5.1)