Description
An improper validation of the search parameter of the com_media files API endpoint leads to a path traversal vulnerability.
Remediation
References
Related Vulnerabilities
WordPress Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2017-5610)
WordPress Plugin uContext for Clickbank Cross-Site Request Forgery (3.9.1)
Nginx Out-of-bounds Write Vulnerability (CVE-2014-0133)
IBM WebSEAL Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2018-1886)